LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files Listed by devman Ransomware Group

HIGH severityUnverified claimHow we verify

promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files Listed by devman Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 15, 2025
promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files Listed by devman Ransomware Group

Reported September 15, 2025.

HIGH
Severity
September 15, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On September 15, 2025, it was disclosed that internal files from promisedland.com.tw were listed for sale by the devman ransomware group following a ransomware attack. Individuals and organisations connected to the site are urged to check whether their information has been exposed and to take any necessary protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure organisations by exfiltrating data and listing victims on dedicated leak sites, often pairing claims of stolen files with ransom demands measured in the millions. These public postings form part of a broader pattern in which threat actors seek payment under threat of further disclosure, leaving affected parties and individuals to assess unverified claims against limited public information.

On 15 September 2025 the group known as devman listed promisedland.com.tw on its leak site, asserting that internal files had been taken in a ransomware attack and referencing a figure of 1 000 000 USD. The number of people affected remains unknown, and independent confirmation of the intrusion or the precise contents of any archive has not been published. The listing itself is a claim by the group rather than verified fact.

What happened

According to the available record, the incident was reported on 15 September 2025. The ransomware group devman placed an entry for promisedland.com.tw on its leak site under the headline that includes the phrasing “h21 million USD\ldots Time Remaining:---BUY Files.” The reported summary associated with the listing states 1 000 000 USD. Public detail states only that internal files were exfiltrated in a ransomware attack. No technical description of the intrusion method, no timeline of compromise, and no confirmed volume of data have been released. The number of individuals whose information may be involved is listed as unknown. Because the sole source of these assertions is the group’s own leak-site posting, the claims remain unverified.

Inside devman

Devman operates as a ransomware actor that follows the now-common double-extortion model: data is copied from a victim network before encryption is applied, after which the group posts the victim’s name on a dedicated leak site and sets a payment deadline. Public reporting on the group describes a pattern of listing organisations across multiple sectors, publishing sample files or directory trees to demonstrate possession, and advertising remaining time before full release. Like other groups of this type, devman typically communicates through Tor-hosted sites and demands cryptocurrency payments. No additional statements by the group specifically about promisedland.com.tw beyond the leak-site listing itself have been recorded in the available facts. The listing therefore stands as an unconfirmed claim of successful intrusion and data theft.

promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files Listed by devman Ransomware Group and its sector

promisedland.com.tw is the domain associated with the organisation named in the listing. Public information about the entity’s precise business activities is limited; the .tw country-code top-level domain indicates a Taiwanese registration. Organisations operating under such domains commonly include commercial enterprises, service providers or content platforms that maintain customer records, employee data, financial documents and internal operational files. A ransomware claim against any such entity raises concern because internal files frequently contain personally identifiable information, contractual details and credentials that can be reused for further fraud or social-engineering attacks. The absence of fuller public disclosure about the organisation’s size or sector means the exact scope of potential impact cannot be quantified from open sources alone.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or record counts is provided. Organisations of this general character typically store employee directories, customer contact lists, invoices, project documents, authentication logs and internal correspondence. Whether any of those categories were among the files claimed by devman is unconfirmed. Because the group’s listing supplies no inventory or sample set that has been independently examined, the precise contents of the alleged archive remain unknown. Readers should treat any assertion of specific data categories beyond “internal files” as speculative until corroborated by the organisation or by forensic analysis.

Why it matters

When internal files leave an organisation’s control, the immediate risks include identity theft, targeted phishing and credential stuffing against individuals whose details appear in the material. Even partial employee or customer records can be combined with data from earlier breaches to create more convincing fraud attempts. For the organisation itself, the consequences may include regulatory notification duties under applicable privacy laws, potential contractual liabilities, and the operational cost of investigating and remediating the intrusion. Because the number of affected people is unknown and the exact data types are undisclosed, the scale of personal harm cannot yet be measured; the mere existence of a public claim, however, is sufficient to warrant caution among anyone who has interacted with the domain.

If your data was in this claimed breach

If you have used services or held an account associated with promisedland.com.tw, treat the claim as a prompt for basic hygiene rather than confirmed exposure. Change passwords on any related accounts, enable multi-factor authentication where available, and monitor financial statements and credit reports for unusual activity. Be alert to unexpected messages that reference the organisation or request personal verification. Because the precise contents of the alleged files remain unconfirmed, there is no public list of affected individuals against which to check. Readers can run a free exposure scan of their email address to determine whether that address has already appeared in other known breach data sets; such a scan provides an additional data point but does not prove or disprove involvement in this specific incident. If you receive direct notification from the organisation, follow the instructions it supplies and retain copies of any correspondence for your records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Attributed to

Method

More recent breaches

promisedland.com.tw Listed by devman Ransomware GroupSeptember 3, 2025pr*****.tw Listed by devman Ransomware GroupAugust 1, 2025***.c*m.tw Listed by devman Ransomware GroupAugust 1, 2025kw****.tw Listed by devman Ransomware GroupAugust 1, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files Listed by devman Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by devman — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram