Ransomware victim disclosure
← All victimsbuben
Claimed by AuditTeam · listed 2 hours ago
Status timeline
- ListedSep 16, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileBuben appears to be a company or organization of unknown sector and scale. No public website or verifiable information is available to confirm its business operations or location.
Attack summary
Severity: medium — Data has been published and is claimed to be complete, but the absence of a public site, verifiable victim identity, and specifics on data type or sensitivity prevents a higher classification. Medium reflects confirmed disclosure without clarity on scope or sensitivity.AuditTeam claims to have acquired data from Buben and published sample evidence and a complete data archive to a public repository. The group does not specify what data was exfiltrated or whether encryption occurred.
What the group claims
buben.it
The leak post
captured from the group's site[[ DATA EXPOSURE LOGS ]](http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/) ### [ EVIDENCE OF ACQUISITION (SAMPLE) ] Sample data artifacts have been published to validate our audit findings. Copy the links below to verify. ### [ PUBLIC TRANSPARENCY ARCHIVE ] The remediation window has expired. The complete acquired data archive is now public.
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

