Dire Wolf Claims Attack Against Coral, C.A.
On November 13, 2025, the Dire Wolf ransomware group claimed to have compromised Coral, C.A., a Venezuelan distributor. The threat actor claimed to have stolen 160 GB of confidential information, including financial, sales, and billing data, as well as a Microsoft SQL Server database. The group threatened to publish the stolen data starting on November 15, 2025. It has not yet been verified whether the data was ultimately leaked or whether the company suffered any financial losses.
Overview
Missing evidence
Impact details
Public sources only confirm an unconfirmed claim by Dire Wolf that 160 GB were stolen from Coral, C.A.; no statement from the victim or independent verification confirms the security breach, encryption, publication of the leak, or service disruption.
Classification & severity
- Category
- Malicious code
- Subtype
- Ransomware
- Confidence
- Medium
RedPacket, BreachSense, and other public sources support a claim by Dire Wolf ransomware/leak site regarding Coral and 160 GB of alleged data. No source validates the encryption, the authenticity of the leaked data, or the service disruption.
Severity assessment
Medium- Information impact
- Suspected
- Affected scope
- Organization-wide
- Critical service
- None
- Public confidence
- Limited
Tracker/leak-site coverage applies only to alleged data breaches; it does not cover confirmed service disruptions, integrity impacts, or recovery impacts.
Timeline
Dire Wolf listed Coral, C.A. as an alleged victim.