Grupolider / Grupo Actual listed by the Deadlock ransomware group
Grupolider / Grupo Actual
Overview
The Deadlock ransomware group has listed Grupolider, an Angolan conglomerate operating since 1999, on its leak site. The group started in freight forwarding and has diversified into agriculture, construction and furniture. The listing also references Grupo Actual, its Portuguese human resources arm. The listing appeared on 10 July 2026, and the group states leaked files will be available for download.

What was published
The group claims to have exfiltrated corporate data from the conglomerate. The archive is expected to include business records, client information and financial documents across the group's operations.
Risks for affected individuals
- Clients and business partners could be targeted using contract data.
- Financial records may facilitate fraud.
- Employee information may be included.
What remains unknown
- The exact volume of data.
- Whether the download link is already active.
- The scope of systems compromised.
What affected people should do
Business partners should verify payment requests through direct channels. The company should notify partners and staff, secure affected systems, and coordinate with Angolan authorities on the response.
Sources
- http://deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion/s3.php?d=d2FzYWJpOmRhdGEtZ3J1cG9hY3R1YWwucHR8ZXUtY2VudHJhbC0xfEFSUjVHRFQzMFJWVERXTE4xWjFOfFByYVRoWFpHNlZmTzZFY2V0ekQ3M3VBSUZselVkcVozc1RpYTRmejA%3D