Ransomware victim disclosure
← All victimsleonardo.com
Claimed by Threeam · listed 1 year ago
Status timeline
- ListedFeb 13, 2025
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Italy
- Sector
- Technology
- Listed on leak site
- Feb 13, 2025
About the victim
AI dossier — public-source company profileLeonardo is a global aerospace, defence, and security company headquartered in Rome, Italy, founded in 1948. It designs and manufactures helicopters, combat systems, aeronautics platforms, cyber & security solutions, electronics, HPC systems, and space defence systems. The company is a major defence contractor serving government and military clients worldwide.
- Industry
- Aerospace, Defence & Security
- Address
- Rome, Italy
- Founded
- 1948
Attack summary
Severity: high — Leonardo is a critical defence contractor with access to sensitive military and government systems. Any confirmed breach of a company of this strategic importance—particularly one handling aerospace, defence electronics, and combat systems—represents a significant national security concern, even without explicit confirmation of data exfiltration in the available post.The Threeam group claims to have attacked Leonardo and published data. No specific details about the nature of the breach (encryption vs. exfiltration), scope of data, or proof materials are provided in the available leak post excerpt.
What the group claims
Leonardo is a global aerospace, defense, and security company providing helicopters, security electronics, aeronautics, and space defense systems. The company was founded in 1948 and is headquartered in Rome, Italy.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

