← Kee Wah Bakery

2026 Kee Wah Bakery — ransomware; DragonForce listing claims ~370GB (Jul 16)

2026 Unknown records affected Share on X

Data compromised

Company June notice: systems hold employee personal data and information on business partners, online-store customers, and mobile-app members; bakery said it could not yet confirm extraction and stated payment/credit-card data was not involved. DragonForce Jul 16 leak-site claim: monitoring attributed an approximate 369.97GB stolen-data figure to the listing—actor volume unverified; no attested individual count

Technical writeup

Company-confirmed ransomware with later DragonForce leak-site listing — June–July 2026. Kee Wah Bakery Co., Ltd., the Hong Kong pastry chain, disclosed that its internal network was hit by ransomware after systems malfunctioned around mid-June 2026; SCMP and The Star reported the company notified employees, customers, and suppliers, engaged cybersecurity experts, and reported the incident to Hong Kong's Privacy Commissioner and police while stating it could not yet confirm whether data was extracted and that payment-card data was not involved. On July 16, 2026, Ransomware.live indexed Kee Wah Bakery on the DragonForce leak site (Hong Kong). Leak-site monitoring circulated an approximate 369.97GB exfiltration claim tied to that listing—BreachHistory treats the gigabyte figure as an unverified actor/reporter claim and indexes recordsAffected 0 pending an attested individual count.

Root cause

Ransomware attack on Kee Wah Bakery internal network (company disclosed mid-June 2026); DragonForce subsequently listed the Hong Kong bakery on its leak site July 16, 2026 claiming large-volume exfiltration

References