ransomware Credible Angola (AO) conglomerate

Grupolider / Grupo Actual listed by the Deadlock ransomware group

Grupolider / Grupo Actual

📅 10 July 2026
CompanyGrupolider / Grupo Actual
CountryAngola (AO)
Sectorconglomerate
Breach date2026-07-10
People affectedNot disclosed
Ransomware groupDeadlock
Data typescorporate records, client data, financial documents

Overview

The Deadlock ransomware group has listed Grupolider, an Angolan conglomerate operating since 1999, on its leak site. The group started in freight forwarding and has diversified into agriculture, construction and furniture. The listing also references Grupo Actual, its Portuguese human resources arm. The listing appeared on 10 July 2026, and the group states leaked files will be available for download.

Grupolider leak listing

What was published

The group claims to have exfiltrated corporate data from the conglomerate. The archive is expected to include business records, client information and financial documents across the group's operations.

Risks for affected individuals

  • Clients and business partners could be targeted using contract data.
  • Financial records may facilitate fraud.
  • Employee information may be included.

What remains unknown

  • The exact volume of data.
  • Whether the download link is already active.
  • The scope of systems compromised.

What affected people should do

Business partners should verify payment requests through direct channels. The company should notify partners and staff, secure affected systems, and coordinate with Angolan authorities on the response.

Sources

  • http://deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion/s3.php?d=d2FzYWJpOmRhdGEtZ3J1cG9hY3R1YWwucHR8ZXUtY2VudHJhbC0xfEFSUjVHRFQzMFJWVERXTE4xWjFOfFByYVRoWFpHNlZmTzZFY2V0ekQ3M3VBSUZselVkcVozc1RpYTRmejA%3D