ACDC Express listed by the Lynx ransomware group
ACDC Express
Overview
The Lynx ransomware group has listed ACDC Express, the South African electrical products retailer and wholesaler, on its leak site. Founded in 1984, the company employs over 700 staff and is headquartered in Johannesburg. This listing, dated 14 February 2025, is a separate incident from the LockBit claim of May 2024. At the time of analysis, the group's leak page was not reachable.
What was published
The group claims to have exfiltrated data from the retailer. The archive is expected to include customer records, order histories and financial information.
Risks for affected individuals
- Customer personal data may be exposed.
- Financial records could enable fraud.
- Employees' information may be included.
What remains unknown
- The volume of data exfiltrated.
- The exact contents of the leak.
- Whether the data has been published elsewhere.
What affected people should do
Customers should monitor their accounts and be cautious of unsolicited communications. ACDC Express should notify affected customers and staff, review its systems, and report the incident to South African authorities.
Sources
- http://lynxblog.net/leaks/67cad56f44fac8dca1b4bc93