On March 12, 2024, Tunisian company ATL appeared on the leak site of the hunters ransomware group. The listing states that the attackers both exfiltrated data and encrypted systems during a ransomware incident. The disclosure does not specify the number of people affected or list exact types of records taken beyond “internal files.”
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ATL
Get alerted the next time ATL files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ATL’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The primary source, hosted on the hunters ransomware portal and indexed by ransomware.live, states that ATL, based in Tunisia, was listed after the group claimed successful data theft and encryption. The entry notes that data was allegedly exfiltrated and systems were encrypted, but provides no sample files, no victim count, and no breakdown of the information involved. As is common with many ransomware leak sites, the posting serves as both proof of compromise and a public shaming mechanism to pressure the victim into payment. The exact date of initial intrusion remains undisclosed by the group or the company.
Why This Matters for You and Your Family
When a company that handles everyday business, supplier, or customer records suffers a breach, the fallout often reaches ordinary people. If you live in Tunisia, have done business with ATL, or have personal information stored in the files the attackers took, your details may now sit on a dark-web server. Even without a precise headcount, the exfiltration of internal files typically includes spreadsheets, contracts, emails, or scanned documents that can contain names, addresses, national identification numbers, phone numbers, or financial details. Once that information leaves the victim’s control, it can be traded, sold, or used to target you or your family with fraud, phishing, or identity theft.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at one dataset. Stolen internal files frequently contain employee directories, vendor lists, or customer spreadsheets that link names to email addresses, phone numbers, and sometimes family-member details. These fragments become building blocks for doxxing chains: an attacker who obtains your work email from the ATL files can cross-reference it with gaming accounts, social-media handles, or breached passwords from unrelated incidents. The result is a detailed profile that can lead to account takeovers, SIM-swapping attempts, or targeted extortion against you or your children. Credential leaks like this one regularly cascade into gaming-platform compromises, where children’s accounts become entry points for further harassment or identity fraud tied to the household address.