RANSOMWARE VICTIMDUPLICATE CLAIM

OCI International Holdings

www.oci-intl.com
ransomhouse📍 HK (HK)📅 October 15, 2025
8
same group

Attack Intelligence

OCI International Holdings was compromised in a ransomware attack attributed to ransomhouse in October 2025. The organization, operating in an undisclosed sector in HK, was added to the group's data leak site as part of an extortion campaign.

ransomhouse operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

OCI International Holdings Limited (stock code: 0329.HK) is a Hong Kong Stock Exchange-listed investment holding company, incorporated in the Cayman Islands in 2001. The company operates through its subsidiary, OCI Asset Management Company Limited, which holds SFC licenses for securities dealing, advising, and asset management, managing bond and private equity funds. Key services include cross-border M&A advisory and securities trading. Related entity OCI Capital SPC, incorporated on August 15, 2017, is a segregated portfolio company with no active portfolios as of January 21, 2025, and was de-registered from CIMA on February 1, 2020. Major shareholders include JZ Investment Fund L.P. (29.34%) and Shanghai Orient Securities Capital (20.94%).

Additional Details

Other Victims — ransomhouse (8)

Quick Facts

CountryHK (HK)
Attack DateOct 15, 2025
Domainwww.oci-intl.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

ransomhouse
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.