The Panzer ransomware operation has been linked to a reported attack on The Minor Food Group, a Thailand-based food and beverage company with thousands of outlets across the Asia-Pacific region. Reporting says the incident was identified on Aug. 10 and framed as a data breach affecting an organization in the agriculture and food production sector, marking one of the first publicly noted victim claims associated with the group.
Separate threat intelligence reporting describes Panzer as an emerging ransomware-as-a-service (RaaS) operation recruiting affiliates on a Russian-speaking cybercrime forum. The group reportedly advertises an 80/20 revenue split, automated affiliate management, negotiation portals, and leak-site support, and claims ransomware builds for Windows, Linux, ESXi, and FreeBSD. Researchers said no public malware sample was available and some capabilities remain unverified, but the Minor Food Group incident suggests Panzer may be moving from recruitment and promotion into active victim operations.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
The ransomware-related breach affecting The Minor Food Group was discovered later the same day. The discovery time was reported as Aug. 10, 2026 at 13:52 UTC.
The Minor Food Group in Thailand was reported as the victim of a ransomware attack attributed to Panzer, involving a data breach affecting the food and beverage company. The breach was dated Aug. 10, 2026 at 10:37 UTC.
Tammy Harper of Flare.io published a LinkedIn post presenting preliminary analysis of a new ransomware-as-a-service operation called Panzer, describing its affiliate recruitment on a Russian-speaking cybercriminal forum and its claimed platform features. The report noted that Panzer's claims were unverified and had not been tied to confirmed attacks at that time.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.