LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Saville Row - Grupo GTD was hacked A huge amount of personal information was stolen Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Saville Row - Grupo GTD was hacked A huge amount of personal information was stolen Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 21, 2023
Saville Row  - Grupo GTD was hacked A huge amount of personal information was stolen Listed by alphv Ransomware Group

Reported April 21, 2023.

HIGH
Severity
April 21, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Saville Row - Grupo GTD was hacked A huge amount of personal information was stolen Listed by alphv Ransomware Group (reported April 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On or around 21 April 2023, Grupo GTD, a Chilean organisation, was listed by the alphv ransomware group as a victim of a cyber attack. Public reporting states that the company was hacked and that internal files were exfiltrated; the same material also references Saville Row in connection with the incident. The number of people affected remains unknown, and independent confirmation of the full scope has not been published in the available record.

For customers, employees and partners of a large telecommunications and technology group, any confirmed or claimed theft of internal files raises practical questions about what information may have left the organisation and how it could be misused. Detail beyond the listing and the description of exfiltrated internal files is limited.

Inside the incident

According to the public breach record, Grupo GTD was reported on 21 April 2023 as having been hacked, with a large amount of personal information described as stolen and with the organisation listed by the alphv ransomware group. The named exposure is internal files exfiltrated in a ransomware attack. No verified figure for the volume of data, no confirmed count of affected individuals, and no public technical account of the initial access method or timeline appear in the available facts. Whether encryption of systems occurred alongside exfiltration, and whether any ransom demand was paid or refused, is undisclosed.

The record also associates Saville Row with the same reporting cluster, providing separate organisational particulars for that entity. The precise operational relationship between Saville Row and Grupo GTD in the context of this incident is not spelled out beyond the joint framing in the headline and summary. Public detail on containment, forensic findings or official notifications to regulators or affected parties is not included in the facts provided.

The group behind it: alphv

Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned as a ransomware-as-a-service model. Affiliates typically gain access to victim networks, move laterally, exfiltrate data, and deploy encryption, after which the group pressures victims by threatening to publish stolen material on a dedicated leak site. The group has been linked in open sources to numerous attacks on organisations across sectors and regions before and around 2023, often emphasising double-extortion: encryption plus the threat of data exposure.

In this case, alphv’s listing of Grupo GTD constitutes a claim by the group that it was responsible and that data was taken. The facts do not independently confirm the group’s full assertions about this victim. Readers should treat leak-site claims as unverified until corroborated by the organisation, regulators or other primary sources. No specific statements attributed to alphv about file counts, ransom sums or publication deadlines for this incident are present in the given record.

About Grupo GTD

Grupo GTD is identified in the record as headquartered at 920 Moneda Piso 11, Santiago, Chile, with contact details including the phone number +56 6009505000 and the website www.gtd.cl. Reported revenue is given as approximately $1 billion. Publicly, GTD operates in telecommunications, connectivity and related technology services in Chile and the region—sectors that routinely handle customer account data, network configuration information, billing records and internal corporate files.

The same reporting block also describes Saville Row, with headquarters listed at 1-2 Carretera General San Martín N° 6900 Km 7, Colina, Santiago Metropolitan, Chile, phone +56 223808200, website www.savillerow.cl, and reported revenue of about $14.4 million. A breach affecting a major telecom and technology group matters because such organisations sit on concentrated stores of personal and operational data and because disruption or data theft can affect service continuity and trust across a wide customer base. The facts do not establish negligence or specific security failures at either entity.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. They do not itemise fields such as names, national identification numbers, financial account details, passwords or health information. The headline language refers to a huge amount of personal information having been stolen, but that characterisation is not broken down into verified data categories in the record.

Organisations of this type typically hold customer contact and service records, employee human-resources files, contracts, network documentation and internal correspondence. Whether any of those categories were among the exfiltrated files in this incident is unconfirmed. The number of people affected is explicitly unknown. Until the organisation or competent authorities publish a clearer inventory, the exact contents of the stolen set should be treated as undisclosed.

The real-world impact

If internal files containing personal or account-related information were taken, affected individuals could face risks such as targeted phishing, social-engineering attempts that reference real account or employment details, or longer-term identity misuse if identity documents or financial data were included. Because the precise data types and headcount are unknown, the severity for any single person cannot be stated from the public record alone.

For Grupo GTD, consequences can include investigative and recovery costs, possible regulatory scrutiny under applicable Chilean and regional data-protection rules, contractual notifications to partners or customers, and reputational damage. Service disruption is possible in ransomware events but is not confirmed here. Saville Row’s separate listing in the same material raises parallel questions for that entity’s stakeholders, again without verified detail on overlap or shared systems.

What to do if you're exposed

If you are a customer, employee or partner of Grupo GTD or the related entities named in the reporting, consider the following practical steps while official confirmation remains limited:

Public detail on this incident remains constrained to the April 2023 reporting date, the alphv listing claim, and the description of exfiltrated internal files. Further clarity depends on disclosures from the organisation or authorities. Stay alert to official updates rather than relying solely on threat-actor claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyGrupo GTD security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Grupo GTD’s full breach history →

More recent breaches

Amber Court 2020 was hacking A lot of customers' personal information was stolen Listed by alphv Ransomware GroupJuly 12, 2023The Dufresne Group - DSG - ASHLEY HOMESTORES Listed by alphv Ransomware GroupJune 18, 2023Voxx Electronics - company, which has a huge number of vulnerabilities was hacked A large Listed by alphv Ransomware GroupMay 24, 2023NAIVAS WAS HACKED A LARGE AMOUNT OF CONFIDENTIAL DATA HAS BEEN STOLEN Listed by alphv Ransomware GroupApril 24, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Saville Row - Grupo GTD was hacked A huge amount of personal information was stolen Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram