EDL Rejects Ransomware Claims from Sinobi Group
The Australian global energy firm EDL has firmly denied any claims of being compromised following allegations made by the relatively new Sinobi ransomware group. This group recently listed EDL on its darknet leak site, marking the company as one of its initial targets.
Understanding the Allegations
On August 9, 2025, the Sinobi group made headlines by including EDL in a list of its victims. This announcement raised concerns within the cyber security community given EDL’s prominence as a producer of sustainable energy. However, the details provided by Sinobi were scant, revealing only the company’s identity and its revenue figures, without any substantiating evidence of an actual breach.
EDL’s Response
In response to these claims, EDL has stated that it conducted a thorough internal investigation, supported by external cyber security experts. An EDL spokesperson clarified, “Following a detailed review, we can confirm that, at this stage, there are no indicators of compromise within EDL’s systems. All of our global sites continue to function safely and without disruption.”
This proactive stance underlines EDL’s commitment to maintaining the integrity and security of its systems and data. The spokesperson further emphasized the company’s seriousness regarding cyber security incidents, affirming that they prioritize the verification of their data’s confidentiality and availability.
The Sinobi Group
Since its emergence in early July, Sinobi has publicly claimed a total of 16 victims. However, the authenticity of its claims remains questionable. Cyber Daily has noted that while Sinobi asserts that it has published sensitive data from some targets, links associated with these disclosures have often turned out to be non-functional.
Ransom Note Insights
Cyber Daily has encountered what is purported to be Sinobi’s ransom note. It contains familiar messaging typical of ransomware communications: “As you can see, you have been attacked by us! We offer you to make a deal with us.” The note further elaborates that the group is not driven by political motives but by financial gain, emphasizing a need for quick negotiations within a week.
It’s worth mentioning that the note exhibits language inconsistencies, suggesting it might not have been written by a native English speaker. This peculiar detail raises additional questions about the professionalism and credibility of the Sinobi group.
Potential Connections to Other Ransomware Groups
Threat intelligence platform DarkFeed has pointed out interesting similarities between Sinobi’s leak site and that of the Lynx ransomware group. They noted that the resemblance comes at a time when Lynx’s activity has notably decreased. This observation invites speculation about a possible link between the two groups, warranting a closer examination as the situation unfolds.
EDL’s Global Operations
Operating a robust portfolio of 81 power and gas facilities across the globe, EDL employs over 600 individuals. This broad operational presence makes the company a significant player in the energy sector, further amplifying the stakes involved should any breach occur.
As the cyber threat landscape continues to evolve, EDL remains vigilant and committed to safeguarding both its infrastructure and stakeholder interests. Cyber Daily is dedicated to monitoring this unfolding story and will provide updates as more information surfaces.


