Ransomware victim disclosure
← All victimsCattani S.p.A.
listed as Cattani · Claimed by Spacebears · listed 5 days ago
Status timeline
- ListedJun 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Spacebears
- Status
- Data leaked
- Country
- Italy
- Listed on leak site
- Jun 10, 2026
- Data size
- 1.6 TB
About the victim
AI dossier — public-source company profileCattani S.p.A., established in 1967 in Italy, is a leader in dental equipment and oil-less compressor manufacturing, exporting globally. The group operates divisions including Esam (industrial field, founded 1984) and Magnolia (chemical disinfectant products for surgical instruments, launched 2003), and has supplied components to aerospace and rail projects including NASA and Eurostar.
- Industry
- Dental Equipment & Industrial Compressors Manufacturing
- Founded
- 1967
Attack summary
Severity: high — Confirmed exfiltration of regulated personal data (PII for employees and clients) and financial documents from a manufacturing company; scale and sensitivity of employee/client data justifies high severity despite no ransom demand or encryption stated.The spacebears group claims to have exfiltrated personal information of employees and clients, financial documents, and approximately 200,000+ files from Cattani S.p.A. The group has published data without stating encryption or demanding ransom.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal information
- client personal information
- financial documents
- business files (200,000+)
What the group claims
Established in 1967, Cattani S.p.A. is now a leader in the dental field, exporting its range of products to all continents. After becoming a publicly limited company in 1981, Cattani S.p.A. founded the division Esam in 1984, extending the group’s business activities into the industrial field. In 2003 Cattani S.p.A. launched Magnolia, a chemical company specialising in the production of detergent disinfectant products for surgery instruments and, in particular, dental aspiration systems.The Cattani group designed and manufactured one of the scientific components in the famous NASA space shuttle. Due to our reputation for reliability, Ferrari Engineering (supplier of the European Space Agency) chose us as one of its prestigious suppliers for the production of a 180 gram compressor, which reached a pressure of 38 bar. The group has also taken part in the Eurostar project, the pride of the Italian railway system, producing the train’s pressurization system.-Personal information of employees and clients -Financial documents- 200 000 + other files https://www.***.it/en/
The leak post
captured from the group's siteEstablished in 1967, Cattani S.p.A. is now a leader in the dental field, exporting its range of products to all continents. After becoming a publicly limited company in 1981, Cattani S.p.A. founded the division Esam in 1984, extending the group’s business activities into the industrial field. In 2003 Cattani S.p.A. launched Magnolia, a chemical company specialising in the production of detergent disinfectant products for surgery instruments and, in particular, dental aspiration systems. The Cattani group designed and manufactured one of the scientific components in the famous NASA space shuttle. Due to our reputation for reliability, Ferrari Engineering (supplier of the European Space Agency) chose us as one of its prestigious suppliers for the production of a 180 gram compressor, which reached a pressure of 38 bar. The group has also taken part in the Eurostar project, the pride of the Italian railway system, producing the train’s pressurization system. -Personal information of employees and clients -Financial documents - 200 000 + other files
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

