Ransomware

Dire Wolf Claims Attack Against Coral, C.A.

On November 13, 2025, the Dire Wolf ransomware group claimed to have compromised Coral, C.A., a Venezuelan distributor. The threat actor claimed to have stolen 160 GB of confidential information, including financial, sales, and billing data, as well as a Microsoft SQL Server database. The group threatened to publish the stolen data starting on November 15, 2025. It has not yet been verified whether the data was ultimately leaked or whether the company suffered any financial losses.

Overview

Missing evidence

It is unclear whether the stolen data was actually leaked or whether the company suffered any material losses.No official statement from Coral, C.A. acknowledging the incident was found.

Impact details

Public sources only confirm an unconfirmed claim by Dire Wolf that 160 GB were stolen from Coral, C.A.; no statement from the victim or independent verification confirms the security breach, encryption, publication of the leak, or service disruption.

160 GB alleged

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
Medium

RedPacket, BreachSense, and other public sources support a claim by Dire Wolf ransomware/leak site regarding Coral and 160 GB of alleged data. No source validates the encryption, the authenticity of the leaked data, or the service disruption.

Severity assessment

Medium
Information impact
Suspected
Affected scope
Organization-wide
Critical service
None
Public confidence
Limited

Tracker/leak-site coverage applies only to alleged data breaches; it does not cover confirmed service disruptions, integrity impacts, or recovery impacts.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

Dire Wolf listed Coral, C.A. as an alleged victim.

Evidence & sources

5 sources