RANSOMWARE VICTIMDUPLICATE CLAIM

The Araneta Group

aranetacity.com
osiris📍 PH (PH)📅 December 10, 2025
2
same group

Attack Intelligence

The Araneta Group was compromised in a ransomware attack attributed to osiris in December 2025. The organization, operating in an undisclosed sector in PH, was added to the group's data leak site as part of an extortion campaign.

osiris operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

The Araneta Group is a private, diversified conglomerate in the Philippines — active in property development, food service, leisure & entertainment, and hospitality — and is composed of five main business units including ACI, Inc., PPI Holdings Inc., Uniprom Inc., Araneta Hotels Inc. and Progressive Development Corporation. aranetacity.com, aranetagroup.com The group employs around 12,000 people. While publicly available consolidated revenue figures for the entire group are not clearly disclosed, one of its listed related entities (separate from the core private group) — Araneta Properties, Inc. (PSE: ARA) — reported gross revenue of ₱706.7 million in 2024

Additional Details

Other Victims — osiris (2)

Quick Facts

CountryPH (PH)
Attack DateDec 10, 2025
Domainaranetacity.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

osiris
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.