RANSOMWARE VICTIM⚠ DUPLICATE CLAIM
Retemex
Retemex.mx
ransomexx📍 Mexico (MX)📅 September 14, 2024
8
same group
Attack Intelligence
Retemex was compromised in a ransomware attack attributed to ransomexx in September 2024. The organization, operating in an undisclosed sector in Mexico, was added to the group's data leak site as part of an extortion campaign.
ransomexx operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Retemex is a virtual mobile operator in Mexico, operating on the country’s 4.5G LTE network. 24883 clients data even with PLAINTEXT PASSWORDS!
Other Victims — ransomexx (8)
Go2Joy (go2joy.vn)
VN · Hospitality and Tourism
Jun 2026
SOGO Auction
—
Apr 2026
GoTip
—
Apr 2026
ADDA (adda.io)
IN · Technology
Mar 2025
Makesworth Accountants
GB · Financial Services
Feb 2025
Lakeshore Title Agency
US · Financial Services
Jan 2025
Grupo Vargas
VE · —
Dec 2024
Brontoo Technology Solutions
IN · Technology
Aug 2024
Quick Facts
CountryMexico (MX)
Attack DateSep 14, 2024
DomainRetemex.mx
Intel Sourceransomware.live
StatusDUPLICATE CLAIM
Threat Group
External Links
Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.