Ransomware victim disclosure
← All victimsBrødrene Alseth AS
listed as BR-ALSETH.NO · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileBrødrene Alseth AS is a Norwegian civil engineering and construction contractor founded in 1949. The company operates across Telemark, Vestfold, and the Østland region, offering services including road and transport infrastructure, municipal technical works, crushed materials, and watercourse projects. It describes itself as a flexible, quality-conscious contractor with a modern machinery fleet.
- Industry
- Civil Engineering & Construction
- Address
- Atråvegen 568, 3656 Atrå, Norway
- Founded
- 1949
Attack summary
Severity: high — Clop is a well-documented, prolific ransomware group known for large-scale data exfiltration; the status is marked data_published, indicating data was actually released. As a construction contractor handling public infrastructure projects, exposed data likely includes employee PII, project/contract details, and financial records, representing significant business and potentially regulated personal data exposure.Clop claims to have compromised Brødrene Alseth AS and the disclosure status is listed as data_published, indicating exfiltration and publication of data. The leak post itself provided no substantive detail due to a queue/redirect page, so specific data categories are not confirmed from the post.
Data the group says was taken
AI dossier — extracted from the leak post- Business/operational documents
- Employee information
- Project records
- Financial records
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

