Skip to content
Leak-site post naming Retemex, captured by ThreatCluster

Retemex

ransomexx

Ransomware leak-site victim intelligence

Data size
1.4MB
Posted
Sep 14, 2024
Country
mexico
Industry
Telecommunications / Mobile operator

Summary

Written by ThreatClusterfrom site fields, file listing, victim profile, leak post, screenshot

Threat actors associated with the group ransomexx claim that Retemex exposed 24,883 client records and plaintext passwords, via a 1.4MB archive (retemex_db.7z) that was published. The archive is password-protected, and the password is Vm14a2QxVXlVbGhVYWxwU1lteEtUMVJXWkc5WFp3. The leak page identifies Retemex as the victim—a small Mexican telecommunications operator headquartered in Mexico City with around 1-10 employees.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Employees
0

What was taken

Retemex is a virtual mobile operator in Mexico, operating on the country's 4.5G LTE network. 4,883 client records exposed in a breach, including passwords stored in plain text .

Data categories
client recordspasswords
File types seen
7z × 1
Sample files (1)
retemex_db.7z

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

The password for each archive is
Vm14a2QxVXlVbGhVYWxwU1lteEtUMVJXWkc5WFp3

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture