ShellCodeX
Tools • Events • News • Insights
Victim Claim

La Kaffa International

thegentlemen 🇮🇹 Italy Agriculture and Food Production lakaffagroup.com
Claimed by thegentlemen
Listed on leak site 06 May 2026
Reported attack date 03 May 2026
Group claims tracked 373
Unverified claim. This entry reproduces a listing published by the thegentlemen group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that La Kaffa International suffered a breach, or what data was actually taken.

About the organisation

lakaffagroup.com zoominfo.com/c/la-kaffa-international-co-ltd/426003975 La Kaffa International is a publicly listed Taiwanese multinational food and beverage group (Taiwan Stock Exchange, code: 2732), founded in 2004 and headquartered in Zhubei City, Hsinchu County, Taiwan, with over 663 employees and annual revenues around $46 million. The company is best known as the parent brand of Chatime — the world-famous bubble tea chain expanded to 50+ countries across 6 continents, making it the top takeout tea brand in Australia, Southeast Asia, and beyond. Beyond Chatime, La Kaffa manages a multi-brand portfolio of 9+ F&B concepts including ZenQ Dessert, Bake Code Bakery, ChunSun Cake, La Kaffa Cafe, Wagokoro Tonkatsu, and Osaka Ohsho Taiwan, with over 1,100 outlets in China alone

What the listing means

La Kaffa International appeared on the thegentlemen leak site on 06 May 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated — the attack itself is dated 03 May 2026, 2 days before the listing. This group has published 134 claims in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing La Kaffa International as suspicious — leaked data gets weaponised for phishing within days.
  • If you hold an account on lakaffagroup.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Agriculture and Food Production organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/TGEgS2FmZmEgSW50ZXJuYXRpb25hbEB0aGVnZW50bGVtZW4=