Summary
Written by ThreatClusterfrom site fields, file listing, victim profile, leak post, screenshotThreat actors associated with the group ransomexx claim that Retemex exposed 24,883 client records and plaintext passwords, via a 1.4MB archive (retemex_db.7z) that was published. The archive is password-protected, and the password is Vm14a2QxVXlVbGhVYWxwU1lteEtUMVJXWkc5WFp3. The leak page identifies Retemex as the victim—a small Mexican telecommunications operator headquartered in Mexico City with around 1-10 employees.
Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.
Victim profile
- Employees
- 0
What was taken
Retemex is a virtual mobile operator in Mexico, operating on the country's 4.5G LTE network. 4,883 client records exposed in a breach, including passwords stored in plain text .
Also stated on the leak page
Fields this group publishes that do not map to a standard column. Labels are the site's own.
- The password for each archive is
- Vm14a2QxVXlVbGhVYWxwU1lteEtUMVJXWkc5WFp3
Leak-site images (1)
Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.