Ransomware victim disclosure
← All victimsIXPERTA
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedMay 15, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- Spain
- Sector
- Technology
- Listed on leak site
- May 15, 2023
About the victim
AI dossier — public-source company profileIXPERTA is a Czech-headquartered IT services and technology solutions company with over 30 years of market presence, more than 300 experts, and annual revenue exceeding 1 billion CZK. The company provides comprehensive IT services including cybersecurity, software development, system integration, IT outsourcing, digitalization, and low-code platforms to both public administration and private-sector clients of all sizes. It operates internationally, having completed 7,000+ projects worldwide, and holds partnerships with vendors such as Atlassian, Mendix, Check Point, Mitel, and Thermo Fisher Scientific.
- Industry
- IT Services & Technology Solutions
- Employees
- 301-500
- Founded
- 1995
Attack summary
Severity: high — Data has been confirmed published by the threat actor. IXPERTA is an IT services and cybersecurity provider serving public administration and enterprises; exfiltration of its internal and client data poses significant business and supply-chain risk, and may include sensitive government/public-sector client information.The Snatch ransomware group claims to have compromised IXPERTA and has published data (disclosed status: data_published), indicating exfiltration of company data; the leak post excerpt references knowledge of customers and solutions delivered to public administration and private companies, suggesting internal business and potentially client-related data is at stake.
Data the group says was taken
AI dossier — extracted from the leak post- Internal business documents
- Customer information
- Public administration project data
- Company operational data
What the group claims
We first get to know each customer thoroughly so that we can design exactly the solution they need. Nothing less and nothing more. That is why we achieve top results in both public administration and companies of all sizes and industries. Whether they are from
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

