Ransomware victim disclosure
← All victimsProfinergy BV
listed as profinrg.nl · Claimed by Settra · listed 7 days ago
Status timeline
- ListedAug 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Settra
- Status
- Data leaked
- Country
- Netherlands
- Sector
- Professional Services
- Listed on leak site
- Aug 11, 2026
About the victim
AI dossier — public-source company profileProfinergy BV (operating as ProfiNRG) is a Dutch renewable energy project developer and engineering, procurement, and construction (EPC) contractor specializing in design, construction, and operation of utility-scale solar power plants across Europe. Headquartered in Utrecht, the company operates through a network of specialized legal entities and dedicated special purpose vehicles (SPVs) for individual solar farm projects, with consolidated group assets of approximately €35 million.
- Industry
- Renewable Energy Development & Solar EPC Contracting
- Address
- Maarssenbroeksedijk 37, 3542 DM Utrecht, Netherlands
Attack summary
Severity: critical — Confirmed exfiltration of multiple categories of highly sensitive regulated and proprietary data: (1) consolidated financial statements and banking details of regulated energy sector company; (2) personal customer data at scale (names, addresses, phone numbers, banking account details); (3) employee personal records including work authorization status; (4) confidential NDA-marked commercial contracts with third parties (Tesla); (5) financing agreements with government bank and critical infrastruThe Settra group claims to have exfiltrated thousands of files from an unprotected archive belonging to Profinergy, including consolidated financial statements, confidential Tesla Energy commercial proposals (€5.1–6.4 million energy storage contracts), BNG Bank financing documents, power purchase agreements, technical manuals from third parties (Ciel & Terre, AXIAL), insurance policies, court litigation records, personal customer and employee data, and supplier chain information.
Data the group says was taken
AI dossier — extracted from the leak post- Consolidated financial statements (€35M+ assets)
- Tesla Megapack NDA commercial proposals
- BNG Bank credit agreements and terms
- Power Purchase Agreements (IJsselmeerdijk, others)
- Insurance policies with coverage amounts
- Third-party technical manuals (Ciel & Terre, AXIAL, Liander)
- Court case files (Astronergy Solar lawsuit 2018)
- Customer accounts receivable with names, addresses, phone numbers
- Employee correspondence with banking details
- Personal customer invoices with full addresses and equipment specs
- Employee work authorization/visa status documents
- JA Solar supplier agreements and procurement pricing
- Huawei inverter and monitoring system credentials (default passwords)
- Project drawings and permits
- Supply chain and vendor relationships
What the group claims
How Profinergy BV Lost Control of Thousands of Files PROLOGUE: Thousands of files. The complete digi...
The leak post
captured from the group's site# How Profinergy BV Lost Control of Thousands of Files **Thousands of files. The complete digital archive of a group of companies building solar power plants across Europe.** Consolidated financial statements totaling over . A Tesla Energy commercial proposal — marked **"Proprietary & Confidential | Disclosed under NDA"** — with three pricing options for Megapack energy storage systems with a combined value ranging from . Credit documents for a solar farm financed by BNG Bank. A power purchase agreement with . Insurance policies with exact coverage amounts. Confidential supplier technical manuals marked . Court documents from a lawsuit against Profinergy — a summons seeking a penalty of . Personal customer data: names, addresses, phone numbers, and banking details for payments. A letter confirming "highly skilled migrant" status — an employee record complete with work authorization. All of it — in a single unprotected archive belonging to (trade name ), a Dutch solar energy developer and EPC contractor headquartered in Utrecht. _This article presents only a portion of the data we have chosen to disclose. The rest will be available for download and review following publication of th…
Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

