← Blog

Kee Wah Bakery: DragonForce Lists HK Chain

Share on X

July 16, 2026: Ransomware group DragonForce listed Hong Kong pastry giant Kee Wah Bakery on its leak site, weeks after the company itself disclosed a mid-June ransomware attack on its internal network. Leak-site monitors floated an approximate 369.97GB stolen-data claim—treat that volume as unverified until Kee Wah or a regulator publishes totals.

What Kee Wah confirmed in June

Per SCMP and The Star, Kee Wah said its internal network malfunctioned in mid-June, a preliminary probe found ransomware, and systems hold employee data plus partner, online-store, and app-member information. The bakery told customers it could not yet confirm extraction, said payment/credit-card data was not involved, notified the Privacy Commissioner and police, and began alerting staff, customers, and suppliers.

What DragonForce added in July

Ransomware.live indexed Kee Wah under DragonForce on July 16, 2026. Actor listings routinely inflate or invent volumes—the ~370GB figure circulating with the listing is not a company-attested headcount.

Who should care

Employees, suppliers, and anyone with a Kee Wah online or app membership account in Hong Kong or overseas markets.

Action items

  1. Ignore leak-archive DMs claiming Kee Wah customer dumps.
  2. Treat supplier invoices carefully—verify bank-detail changes out-of-band.
  3. Rotate work passwords if you used Kee Wah email or VPN credentials.
  4. Watch for phishing that correctly names membership or wholesale accounts.

Canonical record: Kee Wah Bakery 2026 on BreachHistory.