Skaff Group Listed by Rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Skaff Group was listed by the Rhysida ransomware group on October 03, 2026; the group claims to hold data belonging to an undisclosed number of people. Individuals who have had dealings with Skaff Group should check for any direct contact from the organisation and consider protective steps such as monitoring accounts and changing passwords.
Inside the listing
On or around 3 October 2026, the ransomware group known as Rhysida listed Skaff Group on its public leak site. The listing presents Skaff Group as a target and includes promotional claims about material the group says it holds. As of writing, Skaff Group has not publicly confirmed that an incident occurred, that systems were accessed, or that any files left its control. Independent confirmation from a regulator or a recognised breach index is likewise absent from the material provided for this article. People affected, if any, are unknown in public reporting tied to this listing.
According to the listing text associated with the claim, the group advertises a large file set—described as 139,377 files and roughly 268 GB—and markets categories that include human-resources material, banking-related employee and corporate files, payroll-related documents and code, personal images said to have been stored on work systems, and commercial material such as price lists and references to hospitality clients. Those descriptions are the attackers’ own framing. They are not a verified inventory. Timing of any alleged intrusion, initial access method, dwell time, and whether any ransom demand was paid or refused are undisclosed in the available record. A leak-site entry establishes only that a named crew chose to publish an accusation and sample marketing copy; it does not by itself prove theft, completeness, or accuracy of the advertised haul.
Who is Rhysida?
Rhysida is a ransomware operation that has been tracked in public security reporting since 2023. Like many contemporary crews, it is associated with double-extortion tradecraft: encrypting systems where it can, and separately threatening to publish stolen data on a dedicated leak site to pressure victims. The group has been observed targeting organisations across multiple sectors and geographies rather than a single industry niche. Listings on its site typically combine a victim name, countdown or publication staging, and selective file descriptions intended to demonstrate access and raise leverage.
Public write-ups of Rhysida activity emphasise that leak-site posts are part of an extortion narrative. Volume figures, file counts, and sensational category labels serve the crew’s bargaining position. They should be read as claims until a victim, insurer, or authority corroborates them. Nothing in the Skaff Group listing, as summarised here, adds a confirmed technical post-mortem unique to this case beyond what the group chose to advertise.
Who is Skaff Group?
Skaff Group is described in the listing-related summary as a leader in Lebanon in decorative fabrics. Firms in textile and interior-furnishing supply commonly maintain employee records, supplier and customer commercial terms, banking and payroll arrangements, and operational documents needed to run import, warehouse, and sales activity. Some also hold identity documents for HR onboarding, travel, or compliance, and may store mixed personal media if staff use shared servers without strict separation.
A public accusation against a named regional manufacturer matters because employees, contractors, and business partners may worry about identity, financial, and commercial misuse even when the underlying claim remains unverified. Lebanon’s business environment already faces elevated cyber and fraud pressure; leak-site theatre can amplify anxiety and secondary scams that merely name-drop a familiar local employer. That consequence follows from the listing’s visibility, not from any adjudicated finding about Skaff Group’s defences.
What was likely exposed
Structured fields for this incident mark specific exposed data types as not disclosed in a confirmed sense. The Rhysida listing, however, claims a package on the order of 139,377 files and about 268 GB and markets several sensitive categories. According to that listing copy, the group highlights full HR-style dossiers; roughly forty scans of Lebanese national identity cards (both sides plus photos); a director’s passport and civil-status extracts; banking material said to include employee account files at Byblos Bank labelled per person, Cedrus Bank corporate card programme details with banker contacts, and account statements; payroll-related items including an unpaid-salary analysis file, payroll module source code, and staff leave requests; family photo archives allegedly kept on a work server; and commercial content such as price lists and references involving names including Four Seasons and further truncated client wording in the source summary.
None of those items should be treated as a claimed breach inventory. If files of the kinds manufacturers and trading houses typically hold were copied, organisations in this sector often retain national ID and civil documents for employment, bank coordinates for salary payment, payroll systems and leave records, internal price lists, and customer or hospitality-account commercial terms. Exact contents, whether samples were altered or recycled, and whether the advertised volume is accurate remain unconfirmed. Public detail is limited to the attackers’ marketing language and the fact of the listing itself.
What's at stake
If identity scans, passports, or civil-status extracts matching the listing’s claims were genuinely taken, affected individuals could face identity fraud, forged applications, or targeted social engineering that cites real personal details. Banking coordinates and statements, if real, raise risks of attempted account takeover, fraudulent payment instructions, or phishing that impersonates a known bank relationship. Payroll and HR files can expose salary levels, family links, and internal disputes that fuel extortion or workplace harassment. Commercial price lists and client references, if authentic, could disadvantage negotiations or invite competitor and fraudster attention.
For the organisation, the stake is reputational and operational even before any technical confirmation: customers and staff may demand answers, banks may heighten monitoring, and opportunistic criminals often launch follow-on scams that merely exploit the news of a listing. Those harms can occur whether or not the full advertised archive is genuine. Equally, a listing can be exaggerated, partial, or false; treating every claim as settled fact would mislead readers and unfairly fix blame without evidence. What the leak site establishes is an unverified accusation and a pressure campaign—not a court finding, not a regulator’s notice, and not a complete map of what any person actually lost.
What to do now
If you are a current or former Skaff Group employee, contractor, or close partner, proceed on a conditional basis. Watch bank and card activity for unfamiliar transfers or new payees; contact your bank through official channels if something looks wrong. Treat unexpected messages that cite HR, payroll, unpaid salary, or “data recovery” with scepticism—verify independently. If you ever submitted identity scans or passport copies to an employer, consider national guidance on document misuse and fraud reporting in Lebanon. Prefer unique passwords and multi-factor authentication on email and financial accounts so a single leaked credential is less useful. Commercial contacts may wish to confirm recent order and payment changes out-of-band.
Skaff Group has not publicly confirmed this incident as of writing; any personal impact remains unproven in the public record summarised here. Readers who want a practical check can run a free exposure scan of their email address to see whether that address has already appeared in known breach datasets elsewhere, then tighten credentials accordingly. Stay alert to follow-on phishing that name-drops Rhysida or Skaff Group, and rely on official company or bank notices rather than leak-site screenshots when deciding what is real.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Mat Bao Corporation Listed by Rhysida Ransomware GroupKreishandwerkerschaft Borken Listed by Rhysida Ransomware GroupSAD'S Interim Listed by Rhysida Ransomware GroupRug & Home Listed by Rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Skaff Group Listed by Rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.