LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ultrabulk Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Ultrabulk Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 27, 2023
Ultrabulk Listed by alphv Ransomware Group

Reported January 27, 2023.

HIGH
Severity
January 27, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ultrabulk Listed by alphv Ransomware Group (reported January 27, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target industrial and logistics firms, treating operational documents and internal systems as leverage in double-extortion schemes. In late January 2023 one such claim surfaced against Ultrabulk, a bulk-shipping operator, when the alphv ransomware group listed the company on its leak site. Public detail remains limited: the number of people affected is unknown, and the precise contents of any stolen material have not been independently confirmed. What is known is that the listing alleged exfiltration of internal files during a ransomware attack, a pattern consistent with alphv’s established methods and with the broader pressure these groups place on organisations that move physical goods across global supply chains.

For employees, customers, suppliers and other stakeholders, even an unverified claim matters. Shipping companies routinely hold commercial contracts, crew and staff records, voyage data and correspondence that, if exposed, can create fraud, competitive or privacy risks. This article sets out only what has been reported, places the claim in context, and outlines practical steps for anyone who may be concerned.

Breaking down the breach

On 27 January 2023 it was reported that Ultrabulk had been listed by the alphv ransomware group. According to the available summary, the group claimed that internal files had been exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published. The exact date of any intrusion, the initial access method, the duration of access, and whether systems were encrypted or merely copied are all undisclosed in the public record.

The listing itself constitutes a claim by the threat actor rather than an independently verified disclosure by the company. No further technical indicators, ransom demand amounts, or sample file listings have been supplied in the facts available for this account. Readers should therefore treat the scale and success of the alleged operation as unconfirmed pending any official statement or forensic reporting.

The group behind it: alphv

Alphv, also widely known in public reporting as BlackCat, is a ransomware-as-a-service operation that emerged in late 2021. The group is noted for using a Rust-based encryptor, offering affiliates a share of ransoms, and routinely combining encryption with data theft and leak-site pressure. Public analyses of prior alphv activity describe double-extortion tactics: affiliates exfiltrate material, encrypt systems where possible, then threaten to publish stolen data if payment is not made.

Alphv has been linked in open-source reporting to attacks across multiple sectors, including manufacturing, logistics and professional services. The group has at times claimed high-profile victims and has adjusted its branding and infrastructure after law-enforcement actions. None of that broader history proves the specific allegations against Ultrabulk; it only explains why a listing by alphv is treated seriously by defenders and why the group’s claims are monitored. In this case, the sole attribution rests on the leak-site listing reported on 27 January 2023.

Ultrabulk and its sector

Ultrabulk operates in bulk shipping, moving dry bulk commodities by sea. Firms of this type sit inside complex supply chains that connect producers, charterers, ports, insurers and regulators. They typically maintain commercial contracts, vessel and voyage records, crew and shore-staff information, supplier details and internal operational correspondence. The reported summary associated with the incident also references Ultranav’s general business principles and ethical-reporting channels, indicating that Ultrabulk sits within or alongside the wider Ultranav group of shipping interests.

A breach claim against such an organisation is consequential because disruption or data exposure can affect not only the company but counterparties who rely on timely, confidential commercial information. Even when operational sailing continues, the loss of internal files can create lasting secondary risks around fraud, competitive intelligence and regulatory scrutiny.

The information in question

The facts state that the exposed material was described as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as whether the files included personal data, financial records, contracts, credentials or technical schematics—has been disclosed. The number of individuals whose information may have been involved remains unknown.

Organisations in bulk shipping commonly hold employee and crew personal data, customer and charterer contact details, invoices, bills of lading, and internal policy or compliance documents. It is reasonable to note that such categories are typical for the sector; it is not established that any specific category was present in the material alphv claims to hold. Until Ultrabulk or independent investigators publish a verified inventory, the exact contents stay unconfirmed.

Why it matters

For individuals, the concrete risks centre on misuse of any personal or contact data that may have been among the internal files: targeted phishing, business-email compromise attempts that reference real voyages or contracts, or identity-related fraud if identity documents or financial details were stored. Because the affected population size is unknown, people connected to Ultrabulk—staff, crew, suppliers, customers—cannot yet gauge personal exposure with certainty.

For the organisation, the risks include operational distraction, potential contractual or regulatory follow-up, and reputational pressure arising from the public claim itself. Ransomware incidents also frequently lead to secondary attacks that reuse stolen correspondence or credentials. None of these outcomes is proven in the public facts; they are the ordinary consequences that follow when internal files are alleged to have left an organisation’s control.

What to do if you're exposed

If you have a relationship with Ultrabulk or Ultranav—as an employee, crew member, customer or supplier—treat unsolicited messages that reference the company, specific shipments or internal contacts with caution. Prefer official channels when verifying any request for money, credentials or documents. Monitor financial and email accounts for unusual activity and enable multi-factor authentication where available. Consider placing fraud alerts with relevant credit or identity services if you believe personal data may have been involved.

Because Reported Details remain scarce, a practical next step is to check whether your email address has already appeared in other known breach data sets. Free exposure-scan tools can tell you whether that address surfaces in previously compiled collections, giving an early signal that further monitoring or password changes may be warranted. Remain alert to official updates from the company; until more is verified, measured caution is the proportionate response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyUltrabulk security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ultrabulk’s full breach history →

More recent breaches

royaleinternational.com Listed by alphv Ransomware GroupDecember 2, 2023UPDATE! FEAM Maintenance Listed by alphv Ransomware GroupNovember 16, 2023FEAM Maintenance Listed by alphv Ransomware GroupNovember 16, 2023penanshin Listed by alphv Ransomware GroupNovember 5, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Ultrabulk Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram