HackerFeeds
All ransomware incidents
dl-holdings.com

Ransomware group Orova hits DL HOLDINGS GROUP

MEDIUM
·Other·HK·2026-08-19

DL HOLDINGS GROUP — a other target operating in HK has been listed by the Orova ransomware group on 2026-08-19. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationDL HOLDINGS GROUP
Threat Group
Orova
SummaryOur team has taken: 1. Confidential financial records, including unaudited earnings reports, tax filings, and executive compensation details. 2. Internal communications (emails, database, etc.) revealing potential regulatory violations, undisclosed partnerships. 3. Customer and employee PII (Personally Identifiable Information), including passport scans, employment contracts, and NDA-protected agreements. 4. Board meeting minutes and strategic planning documents. 5. Cryptocurrency Investment Plans and progress reports
Date of Breach2026-08-19
Discovery Date2026-08-19
RegionHK
Target Domainwww.dl-holdings.com/en
Business SectorOther
Severity
MEDIUM

Claim by Orova

Our team has taken: 1. Confidential financial records, including unaudited earnings reports, tax filings, and executive compensation details. 2. Internal communications (emails, database, etc.) revealing potential regulatory violations, undisclosed partnerships. 3. Customer and employee PII (Personally Identifiable Information), including passport scans, employment contracts, and NDA-protected agreements. 4. Board meeting minutes and strategic planning documents. 5. Cryptocurrency Investment Plans and progress reports

Posted by the Orova threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

www.dl-holdings.com/en

Leak post (onion / Tor)

tor

http://maa2yprc5pldyr5hjn246hw7i66wdhglnostqgqkcbuh4vyyeos4xxyd.onion/zbadosrctherxvxmev/

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.