Skip to content
Leak-site post naming awwg.com, captured by ThreatCluster

awwg.com

underground

Ransomware leak-site victim intelligence

Posted
May 1, 2024
Country
Spain, France, U...
Industry
Manufacturing

Summary

Written by ThreatClusterfrom site fields, file listing, victim profile, leak post

The leak states that financial and legal documents dating back to 1987, along with privileged, confidential information and personal data on employees, were taken from awwg.com. The material is described as including employee PII (passports, IDs, addresses, emails, SSNs), NDAs, payroll data, contracts, shareholder agreements, and designs and upcoming collections. The leak page identifies the victim as All We Wear Group (awwg.com), a Spain-based fashion company with brands Pepe Jeans, Hackett and Façonnable, and subsidiaries pepejeans.com, hackett.com, faconnable.com; revenue €585 million. The publication status on the leak page is published.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

The All We Wear Group, owner of fashion brands Pepe Jeans, Hackett and Façonnable, as well as distributor in Spain and Portugal of Calvin Klein and Tommy Hilfiger. AWWG conducts business worldwide.

Data categories
financial and legal documentspersonally identified information about employeespassports, IDs, addresses, emails, SSN, phone numbersNDA Agreementscompany accounting and financial data by regionpayroll data and commissionsthe company’s incidentscontracts and all sort of agreementsshareholder agreements and equity documentsbusiness projectsdesigns and upcoming collections (confidential)personal data of company's executives

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

subsidiary_units
["pepejeans.com", "hackett.com", "faconnable.com"]

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture