SEAQUEST SEAFOOD Listed by frag Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SEAQUEST SEAFOOD has been listed by the frag ransomware group, with the disclosure made public on March 14, 2025. An undisclosed number of people may have been affected; individuals are advised to check whether their information was involved and take protective steps.
Ransomware groups continue to target mid-sized companies across supply chains, using data theft as leverage even when operational disruption is the primary goal. In this climate, listings on criminal leak sites have become a routine way for attackers to pressure victims and advertise their capabilities. On 14 March 2025 the ransomware group known as frag publicly listed SEAQUEST SEAFOOD, claiming it had stolen internal files during a ransomware attack. The number of people affected remains unknown, and independent confirmation of the breach details has not been published. For employees, clients and partners of a seafood processor and wholesaler, the listing raises practical questions about what information may now be circulating and what steps are worth taking.
Public reporting so far rests entirely on the group’s own claims. No official statement from SEAQUEST SEAFOOD confirming or denying the incident has been incorporated into the available record, so the account below treats the leak-site posting as an unverified assertion rather than established fact.
What happened
According to the listing dated 14 March 2025, the frag ransomware group claims to have conducted a ransomware attack against SEAQUEST SEAFOOD and to have successfully exfiltrated a collection of internal files. The group states that the stolen material includes financial statements, contact information for clients and employees, partnership agreements, licences and contracts, corporate inspection results, employee and client Social Security numbers, driving licences, and Human Resources documents. No further technical details—such as the initial access vector, the encryption status of systems, the precise volume of data, or the exact date of the intrusion—have been disclosed in the public record. The number of individuals whose information may be involved is listed as unknown. Because these particulars come solely from the threat actor’s own post, they should be regarded as claims pending independent verification.
The group behind it: frag
frag is a ransomware operation that follows the now-common double-extortion model: encrypting systems while simultaneously stealing data and threatening to publish it if a ransom is not paid. Like many contemporary groups, it maintains a leak site on which it names victims and sometimes releases sample files to demonstrate the authenticity of its claims. Public reporting on frag has described a pattern of opportunistic targeting of organisations that hold valuable commercial or personal data, with the goal of maximising pressure through both operational disruption and reputational risk. The group’s listing of SEAQUEST SEAFOOD fits this established pattern, but the specific assertions made about this victim—what was taken and how—remain unverified claims rather than confirmed findings.
Who is SEAQUEST SEAFOOD?
SEAQUEST SEAFOOD is a company that specialises in the processing, import and wholesale distribution of seafood. Businesses of this type typically maintain records of suppliers, commercial customers, logistics partners, quality-control inspections, and their own workforce. They also handle financial documentation, contracts and regulatory filings that are essential to day-to-day operations. A ransomware incident affecting such an organisation can therefore touch both commercial confidentiality and the personal data of employees and clients. Because seafood supply chains often involve multiple intermediaries and regulatory oversight, any compromise of inspection results, licences or partnership agreements can create secondary complications beyond the immediate data exposure.
What data was at risk
The frag group claims that the following categories of material were exfiltrated: financial statements of the company; contact information of clients and employees; partnership agreements, licences and contracts; corporate inspection results; employee and client Social Security numbers; driving licences; and Human Resources documents. These are the only data types named in the available record. No independent inventory or confirmation of the exact contents has been published, and the total volume of data remains undisclosed. Organisations in the food-processing and wholesale sector commonly hold precisely these kinds of records—payroll and tax identifiers, identity documents for employment verification, customer contact lists, and regulatory paperwork—so the claimed set is consistent with what such a firm would be expected to possess. Nevertheless, until verified by the company or by forensic investigators, the precise scope and accuracy of the group’s list cannot be treated as established fact.
What's at stake
If the claimed data are authentic and complete, individuals whose Social Security numbers, driving-licence details or contact information appear in the files face elevated risks of identity theft, fraudulent account openings and targeted phishing. Employees could see HR records used for social-engineering attacks against the company or against them personally. Clients whose contact details and contractual information were taken may receive convincing but fraudulent communications that reference real business relationships. For SEAQUEST SEAFOOD itself, the exposure of financial statements, inspection results and partnership agreements could affect commercial negotiations, regulatory standing and customer confidence, even if systems are restored. Because the number of affected people is unknown, the scale of any subsequent misuse cannot yet be measured; the practical consequence is simply that anyone who has done business with or worked for the company should treat the possibility of exposure as real until clearer information emerges.
Were you affected?
If you are a current or former employee, client or partner of SEAQUEST SEAFOOD, begin by monitoring financial accounts and credit reports for unfamiliar activity, and consider placing a fraud alert or credit freeze with the major credit bureaux. Be alert to unsolicited messages that reference the company or that request personal or financial details. Change passwords on any accounts that may have shared credentials with work systems, and enable multi-factor authentication wherever it is available. Because the full list of compromised records has not been independently published, the only reliable way to check whether your own email address has already appeared in known breach data is to run a free exposure scan. Doing so provides a concrete starting point while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Source Photonics Listed by frag Ransomware GroupSouthwest Inspection and Testing Listed by frag Ransomware GroupCalifornia Gasket and Rubber Corporation Listed by frag Ransomware GroupBunting Capital Management Inc Listed by frag Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the SEAQUEST SEAFOOD Listed by frag Ransomware Group →
Publicly posted by frag — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.