Ransomware victim disclosure
← All victimsColacem
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Italy
- Sector
- Manufacturing
- Listed on leak site
- Jan 17, 2026
About the victim
AI dossier — public-source company profileColacem S.p.A. is an Italian cement and hydraulic binders manufacturer headquartered in Gubbio (PG), Italy, with operations spanning Italy, Spain, Albania, Tunisia, and the Dominican Republic. The company operates multiple production plants and mining areas, and participates in sustainability initiatives including recognition by the UN Global Compact. It is registered as a Società per Azioni Unipersonale with a share capital of €100,000,000.
- Industry
- Cement & Hydraulic Binders Manufacturing
- Address
- Via della Vittorina, n. 60 – 06024 - Gubbio (PG) - Italy
Attack summary
Severity: medium — Data is marked as published (exfiltration confirmed), but no specific data types, volume, or proof files are described in the leak post excerpt, preventing classification as high or critical. The company is an industrial manufacturer, not a regulated/sensitive sector.The Qilin ransomware group has listed Colacem under a disclosed/data-published status, indicating that data exfiltrated from the company has been or is being published. No specific ransom amount or data size has been stated in the post.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

