Ransomware victim disclosure
← All victimsRestart Srl
listed as RSTRT.IT · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileRestart Srl is an Italian managed services and systems integrator company headquartered in Genova, with branches in Rapallo, La Spezia, and Alessandria. Founded in April 2021 through the merger of Superba Telecomunicazioni Srl and Tonex Srl, it provides telecommunications, office automation, IT infrastructure, and green energy solutions. The company serves over 1,000 customers and has more than 20 international installations, staffed by 23 dedicated employees.
- Industry
- IT Services & Telecommunications
- Address
- Corso A. Saffi, 1 – 16128 Genova, Italy
- Employees
- 11-50
- Founded
- 2021
Attack summary
Severity: medium — Data is marked as published by Clop, a sophisticated ransomware group known for large-scale exfiltration campaigns, but no specific data inventory, volume, or regulated data categories are confirmed from the leak post. The victim is a small Italian IT/telco MSP, which may hold sensitive client data, warranting at least medium severity.The Clop ransomware group has listed Restart Srl under a disclosed/data-published status, indicating data has been published or made available. The leak post content is not detailed enough to confirm specific data types exfiltrated or whether encryption occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Business operational data
- Customer records
- Internal company documents
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

