Ransomware victim disclosure
← All victimsBonava
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- Sweden
- Sector
- Manufacturing
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileBonava is a Swedish real estate developer and builder specializing in new residential construction and active lifestyle communities. The company generates approximately SEK 8 billion in annual revenue and operates residential property development projects across Sweden.
- Industry
- Real Estate Development & Residential Construction
Attack summary
Severity: high — Confirmed exfiltration and publication of 842,000 records including significant PII, property ownership data, and customer information at scale. While not explicitly regulated healthcare/financial data, the volume and types of personal and property data represent substantial privacy and identity risk to affected individuals.ExfilSquad claims to have exfiltrated approximately 842,000 records containing personal information, property ownership data, warranty/repair records, contractor details, and customer preferences from Bonava. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Personal Identifiable Information (PII)
- Property ownership records
- Property interest/investment data
- Warranty and repair case files
- Contractor information
- Marketing preferences
- Customer service history
What the group claims
Revenue: SEK 8B DATA SUMMARY: 842K~ records containing: significant PII, property ownership/interests, warranty and repair cases, contractor information, marketing preferences, and customer service history.
Sources
- Victim sitebonava.se
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

