LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › SHUKAKU-INC Listed by walocker Ransomware Group

HIGH severityUnverified claimHow we verify

SHUKAKU-INC Listed by walocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 10, 2025
SHUKAKU-INC Listed by walocker Ransomware Group

Reported June 10, 2025.

HIGH
Severity
June 10, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

SHUKAKU-INC was listed on June 10, 2025 by the walocker ransomware group, which claims to have exfiltrated internal files. Individuals whose information may have been exposed are urged to review their accounts and monitor for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside a Cambodian real-estate developer's systems now face the ordinary but serious possibility that those details have left the organisation's control. On 10 June 2025 the ransomware group known as walocker publicly listed SHUKAKU-INC, stating that internal files had been taken. The number of individuals affected remains unknown, and the precise contents of the files have not been independently confirmed. For anyone who has ever dealt with the firm—employees, contractors, landowners, buyers or partners—the listing raises concrete questions about identity theft, financial fraud and unwanted contact.

Public detail is limited to the group's claim and the bare fact of an alleged ransomware incident. That scarcity of verified information is itself part of the risk: without clear notice, people cannot easily judge whether they need to act.

What happened

According to the available record, SHUKAKU-INC was listed by the walocker ransomware group on 10 June 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No independent confirmation of the intrusion, the encryption of systems, or the volume of data has been published. The number of people whose information may be involved is recorded as unknown. Timing of the initial compromise, the method of entry, and any ransom demand remain undisclosed. The only concrete claim on record is the group's own leak-site entry naming the company and stating that internal files had been taken.

Inside walocker

Walocker is a ransomware operation that follows the now-common double-extortion model: after gaining access, operators encrypt systems and simultaneously copy data, then threaten to publish the stolen material if payment is not made. Groups of this type typically maintain a public leak site where they name victims and, in some cases, release sample files or full archives. Their listings are claims, not verified reports; they serve both as pressure on the victim and as advertising for the group's capabilities. Prior public activity by walocker has involved a range of commercial and industrial targets, with the same pattern of data theft followed by timed publication threats. Nothing in the present record states that walocker has released any SHUKAKU-INC files beyond the initial listing itself.

SHUKAKU-INC and its sector

SHUKAKU-INC is a private real-estate development firm based in Cambodia and active principally in Phnom Penh. It has been associated with large urban projects, including the Phnom Penh City Center development, and has drawn public attention and criticism over land-acquisition practices and related legal disputes. Real-estate developers of this scale routinely hold extensive internal records: land titles and survey data, contracts with landowners and government agencies, financial ledgers, employee and contractor files, and correspondence with buyers and investors. Because the firm operates at the intersection of property rights, urban planning and capital investment, a breach of its systems can affect not only staff but also private citizens whose land or personal details appear in project documentation. The sector's reliance on long-lived paper and digital archives makes the potential exposure of historical as well as current records a practical concern.

The information in question

The only data type named in the available facts is "internal files" said to have been exfiltrated. No further breakdown—customer lists, financial statements, identity documents, or otherwise—has been disclosed. Organisations of this kind typically store land-ownership records, contracts, employee personal data, banking details and project correspondence. Whether any of those categories are present in the material claimed by walocker is unconfirmed. Readers should therefore treat every specific data type as possible rather than established.

The real-world impact

For individuals, the practical risks are familiar: fraudulent use of identity or financial information, targeted phishing that references real projects or land dealings, and the long-term difficulty of correcting records once they circulate. Landowners or buyers whose documents appear in internal files may face particular exposure if those documents contain national ID numbers, addresses or bank details. For the organisation itself, the consequences include operational disruption, potential regulatory scrutiny under Cambodian data-protection rules, loss of commercial confidence among partners, and the cost of forensic investigation and system recovery. Because the number of affected people is unknown and the exact files remain unverified, both the human and institutional impact cannot yet be quantified with precision.

Were you affected?

If you have ever been an employee, contractor, landowner, buyer or business partner of SHUKAKU-INC, treat the listing as a prompt to take basic protective steps rather than as proof that your data has already been misused.

Public confirmation of the breach remains limited to the group's claim. Until SHUKAKU-INC or independent investigators release further verified detail, caution and routine hygiene remain the most useful responses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySHUKAKU-INC security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See SHUKAKU-INC’s full breach history →

More recent breaches

ChokChey Finance Listed by incransom Ransomware GroupFebruary 2, 2026esopdirect.com Listed by lockbit5 Ransomware GroupDecember 30, 2025Lakeside Title Company Listed by play Ransomware GroupDecember 29, 2025Jennings SD Listed by devman Ransomware GroupDecember 27, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the SHUKAKU-INC Listed by walocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by walocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram