SHUKAKU-INC Listed by walocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SHUKAKU-INC was listed on June 10, 2025 by the walocker ransomware group, which claims to have exfiltrated internal files. Individuals whose information may have been exposed are urged to review their accounts and monitor for unusual activity.
People whose personal or professional details sit inside a Cambodian real-estate developer's systems now face the ordinary but serious possibility that those details have left the organisation's control. On 10 June 2025 the ransomware group known as walocker publicly listed SHUKAKU-INC, stating that internal files had been taken. The number of individuals affected remains unknown, and the precise contents of the files have not been independently confirmed. For anyone who has ever dealt with the firm—employees, contractors, landowners, buyers or partners—the listing raises concrete questions about identity theft, financial fraud and unwanted contact.
Public detail is limited to the group's claim and the bare fact of an alleged ransomware incident. That scarcity of verified information is itself part of the risk: without clear notice, people cannot easily judge whether they need to act.
What happened
According to the available record, SHUKAKU-INC was listed by the walocker ransomware group on 10 June 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No independent confirmation of the intrusion, the encryption of systems, or the volume of data has been published. The number of people whose information may be involved is recorded as unknown. Timing of the initial compromise, the method of entry, and any ransom demand remain undisclosed. The only concrete claim on record is the group's own leak-site entry naming the company and stating that internal files had been taken.
Inside walocker
Walocker is a ransomware operation that follows the now-common double-extortion model: after gaining access, operators encrypt systems and simultaneously copy data, then threaten to publish the stolen material if payment is not made. Groups of this type typically maintain a public leak site where they name victims and, in some cases, release sample files or full archives. Their listings are claims, not verified reports; they serve both as pressure on the victim and as advertising for the group's capabilities. Prior public activity by walocker has involved a range of commercial and industrial targets, with the same pattern of data theft followed by timed publication threats. Nothing in the present record states that walocker has released any SHUKAKU-INC files beyond the initial listing itself.
SHUKAKU-INC and its sector
SHUKAKU-INC is a private real-estate development firm based in Cambodia and active principally in Phnom Penh. It has been associated with large urban projects, including the Phnom Penh City Center development, and has drawn public attention and criticism over land-acquisition practices and related legal disputes. Real-estate developers of this scale routinely hold extensive internal records: land titles and survey data, contracts with landowners and government agencies, financial ledgers, employee and contractor files, and correspondence with buyers and investors. Because the firm operates at the intersection of property rights, urban planning and capital investment, a breach of its systems can affect not only staff but also private citizens whose land or personal details appear in project documentation. The sector's reliance on long-lived paper and digital archives makes the potential exposure of historical as well as current records a practical concern.
The information in question
The only data type named in the available facts is "internal files" said to have been exfiltrated. No further breakdown—customer lists, financial statements, identity documents, or otherwise—has been disclosed. Organisations of this kind typically store land-ownership records, contracts, employee personal data, banking details and project correspondence. Whether any of those categories are present in the material claimed by walocker is unconfirmed. Readers should therefore treat every specific data type as possible rather than established.
The real-world impact
For individuals, the practical risks are familiar: fraudulent use of identity or financial information, targeted phishing that references real projects or land dealings, and the long-term difficulty of correcting records once they circulate. Landowners or buyers whose documents appear in internal files may face particular exposure if those documents contain national ID numbers, addresses or bank details. For the organisation itself, the consequences include operational disruption, potential regulatory scrutiny under Cambodian data-protection rules, loss of commercial confidence among partners, and the cost of forensic investigation and system recovery. Because the number of affected people is unknown and the exact files remain unverified, both the human and institutional impact cannot yet be quantified with precision.
Were you affected?
If you have ever been an employee, contractor, landowner, buyer or business partner of SHUKAKU-INC, treat the listing as a prompt to take basic protective steps rather than as proof that your data has already been misused.
- Monitor bank and credit accounts for unexpected activity and enable transaction alerts where available.
- Change passwords on any accounts that may have shared credentials or email addresses with the firm, and enable multi-factor authentication.
- Be sceptical of unsolicited emails, calls or messages that reference land deals, contracts or internal project names; verify through known official channels.
- Request a free credit report or equivalent local credit check if your jurisdiction provides one, and place fraud alerts if appropriate.
- Run a free exposure scan of your email address against known breach data sets to see whether your address has already appeared in other incidents.
Public confirmation of the breach remains limited to the group's claim. Until SHUKAKU-INC or independent investigators release further verified detail, caution and routine hygiene remain the most useful responses.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ChokChey Finance Listed by incransom Ransomware Groupesopdirect.com Listed by lockbit5 Ransomware GroupLakeside Title Company Listed by play Ransomware GroupJennings SD Listed by devman Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the SHUKAKU-INC Listed by walocker Ransomware Group →
Publicly posted by walocker — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.