RICHARD MILLE ASIA PTE. LTD & D'LEAGUE PTE. LTD. Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
RICHARD MILLE ASIA PTE. LTD and D'LEAGUE PTE. LTD. were listed by the lynx Ransomware Group on June 27, 2025, after internal files were taken in a ransomware attack. Anyone connected to either company should check whether their information was exposed and take steps to protect themselves.
When a company that sits inside a private holding structure appears on a ransomware group's listing, the practical concern is not abstract brand damage. It is whether internal files that may contain employee records, partner details, customer information or commercial correspondence have left the organisation's control. For anyone who has worked with, supplied, or bought from businesses linked to Dave Tan's holdings, the question is whether their own data was among the material claimed to have been taken.
Public reporting on 27 June 2025 stated that RICHARD MILLE ASIA PTE. LTD and D'LEAGUE PTE. LTD. had been listed by the lynx ransomware group, with the claim that internal files had been exfiltrated. The number of people affected remains unknown, and the precise contents of those files have not been itemised beyond the general description of internal material from companies inside the holding.
What happened
According to the available public record, the lynx ransomware group listed RICHARD MILLE ASIA PTE. LTD and D'LEAGUE PTE. LTD. on or around 27 June 2025. The listing asserts that internal files were exfiltrated during a ransomware attack and that the data originated from various companies within Dave Tan's holding. No confirmed figure for the volume of data, no confirmed list of file types beyond "internal files," and no confirmed timeline of the intrusion itself have been published in the material provided. Whether encryption of systems occurred, whether a ransom demand was issued, and whether any negotiation took place are all undisclosed. The listing itself is a claim by the group; independent verification of the full scope has not been detailed in the public summary.
The group behind it: lynx
Lynx is a ransomware operation that has appeared in public threat reporting as a group practising double-extortion tactics: encrypting systems where possible while also copying data and threatening to publish it if payment is not made. Like other contemporary ransomware actors, lynx typically maintains a leak site on which it names victims and, in some cases, releases samples or larger archives of stolen material. The group has been observed targeting organisations across multiple sectors rather than specialising in a single industry. Its public listings function both as pressure on the named organisation and as a signal to other potential victims. In this instance the group claims to have taken internal files from the named Singapore-registered entities and related companies inside the holding; those claims should be treated as assertions by the actor until corroborated by the organisations themselves or by independent forensic reporting.
Who is RICHARD MILLE ASIA PTE. LTD & D'LEAGUE PTE. LTD. Listed by lynx Ransomware Group?
RICHARD MILLE ASIA PTE. LTD. is the Asian corporate vehicle associated with the Swiss luxury watchmaker Richard Mille, a brand that operates in the high-end watch and lifestyle market. D'LEAGUE PTE. LTD. appears in the same listing and is described in the public summary as connected to companies inside Dave Tan's holding. Organisations of this type typically maintain records of employees, authorised dealers, high-net-worth clients, logistics partners, and internal financial and operational documents. Because luxury-goods businesses handle both personal data of customers and commercially sensitive information about pricing, inventory and distribution, a breach that reaches internal files can affect individuals and counterparties who never expected their details to leave the company's systems. The listing therefore carries consequences beyond the two named legal entities: it touches the wider set of companies and people who interact with that holding structure.
The information in question
The only data category named in the public facts is "internal files exfiltrated in ransomware attack," with the additional note that the material relates to various companies in Dave Tan's holding. No further breakdown—such as whether the files include customer databases, employee HR records, contracts, financial statements or email archives—has been disclosed. Organisations in the luxury retail and holding-company sector commonly hold names, contact details, purchase histories, passport or identity documents for high-value clients, payroll and HR data for staff, and commercial agreements with suppliers and distributors. Whether any of those categories were actually present in the material claimed by lynx remains unconfirmed. Readers should therefore treat the exposure as involving internal corporate files of unknown composition rather than as a verified leak of any specific personal-data field.
What's at stake
For individuals whose information may have been inside those files, the concrete risks are identity misuse, targeted phishing that references real commercial relationships, and the long-term recirculation of personal details on criminal forums. For the organisations, the stakes include regulatory notification duties under Singapore's personal-data protection regime, potential contractual claims from partners, and the operational cost of investigating and containing the incident. Because the number of people affected is unknown and the exact file contents are unconfirmed, the scale of harm cannot yet be quantified; the prudent assumption is that anyone who has had a documented relationship with the named entities or the wider holding should treat the possibility of exposure seriously.
- Personal data that may have been held could enable social-engineering attacks that appear legitimate.
- Commercial documents, if present, could reveal pricing, supplier terms or client lists to competitors or fraudsters.
- Employees and contractors face the usual risks of credential stuffing and payroll-related fraud if HR material was taken.
- The organisations themselves face reputational and compliance consequences regardless of whether a ransom was paid.
Were you affected?
If you have been an employee, customer, supplier or partner of RICHARD MILLE ASIA PTE. LTD., D'LEAGUE PTE. LTD., or other companies inside the same holding, treat the listing as a reason to increase vigilance rather than as proof that your specific records were taken. Change passwords on any accounts that reused credentials linked to those relationships, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Watch for phishing messages that reference luxury purchases, employment, or business dealings with the group. You can also run a free exposure scan of your email address against known breach data sets to see whether your address has already appeared in other incidents; that check will not confirm or rule out involvement in this particular event, but it provides a practical baseline. Official statements from the companies, if and when they are issued, remain the primary source for confirmation of scope and for any guidance they offer to affected parties.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Bounds Gillespie Killebrew Tushek Architects Listed by lynx Ransomware GroupOptions Listed by lynx Ransomware Grouphttps://www.ckm-montagen.de/en/ Listed by lynx Ransomware Grouphttps://www.omnibusjp.com Listed by lynx Ransomware GroupLatest breaches
Publicly posted by lynx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.