ATL listed by the hunters ransomware group
ATL
Overview
On 12 March 2024, the Hunters International ransomware group listed ATL on its data leak site. ATL, based in Tunisia with the domain atl.com.tn, was presented with confirmation that data was exfiltrated and systems encrypted. The listing appeared in a period of sustained Hunters International activity across Africa.
What was published
The Hunters International listing for ATL confirmed exfiltration and encryption but did not include a record count or a data inventory. The group has released archives for other victims, but no download associated with ATL was observed during the analysis window.
Risks for affected individuals
Employees and customers of ATL could be exposed if personnel records, client databases or financial documents were stolen. Such data enables phishing, fraud and identity misuse, particularly if personal identifiers were part of the exfiltration.
What remains unknown
The volume and types of data taken, and whether the group published any portion of it, remain unconfirmed. No official statement from ATL about the incident has been identified.
What affected people should do
Customers should monitor accounts for unusual activity and treat unsolicited messages with caution. Employees should reset passwords, enable multi-factor authentication, and report any suspicious communication referencing the company.
Sources
- https://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion/companies/6859744306