Ransomware victim disclosure
← All victimsDustin Group AB
listed as Dustin Group · Claimed by Fulcrumsec · listed 2 days ago
Status timeline
- ListedSep 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Fulcrumsec
- Status
- Data leaked
- Country
- Sweden
- Sector
- Technology
- Listed on leak site
- Sep 11, 2026
About the victim
AI dossier — public-source company profileDustin Group AB is a Swedish IT reseller and distributor operating customer-facing portals (Skyportal) and procurement systems. The company serves major Nordic and European institutional customers including banks, police, healthcare systems, and energy providers across multiple countries.
- Industry
- IT Reseller & Distributor
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated sensitive data: over 1 million customer identity records, 92 Swedish personal identity numbers (PII), financial data (IBANs, banking instructions, invoicing), CRM records on high-profile institutional customers in defense, policing, banking, and healthcare sectors, internal security assessments, and source code. The breach exposes data of Dutch National Police, Rabobank, Statnett, ABN AMRO, healthcare systems (Erasmus MC, UMCG, Radboud UMC) and othFulcrumSec claims exfiltration of 6.2 TB of data including 1,041 git repositories with 24.5 million lines of source code, customer identity records (1.05+ million accounts), Jira/Confluence archives, CRM data covering major institutional customers, product and finance databases, and security assessment documents. The group alleges the company hired an incident response firm previously used in a failed negotiation with FulcrumSec during the Novo Nordisk incident.
Data the group says was taken
AI dossier — extracted from the leak post- 1,041 git repositories with full development history
- 24.5 million lines of source code
- 5 TB container images
- 1,058,417 customer identity records (names, emails, account status)
- Skyportal customer identity store
- Internal directory and Azure infrastructure-as-code
- 501,564 Jira issue and comment files (2019–Aug 2026)
- Dynamics 365/Dataverse CRM (23,030 accounts, 27,761 contacts)
- 2.77 GB SQL Server backup (product, finance, supplier data)
- 92 Swedish personal identity numbers
- 15 checksum-valid IBANs and banking instructions
- Nine customer security assessment decks
- Security incident playbooks and compliance documentation
Original description
AI-summarised, not from the leak postDustin Group is a Swedish technology reseller and IT solutions provider headquartered in Stockholm, Sweden. The company operates primarily in the Nordic and Benelux regions, offering hardware, software, and IT services to businesses and public sector organizations. Its product portfolio includes computers, networking equipment, and cloud solutions. Dustin serves both SMBs and large enterprises, positioning itself as a one-stop shop for IT procurement and digital transformation support.
The leak post
captured from the group's siteDustin Group AB • IT Reseller • 6.2 TB total holdings [TORRENTS AVAILABLE — SEE TABLE BELOW](http://4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion/dustin/#initial-release) 6.2 TB total holdings • 1,041 git repositories • 24.5 million lines of code • ~5 TB of container images • 1,058,417 named identity records • 501,564 Jira issue and comment files • 92 Swedish personal identity numbers • nine customer security assessments Today we are making the Dustin Group breach public. We hold the source code behind its webshops and customer portal, its customer identity store, internal directory, Atlassian estate, CRM, product databases and finance integrations. The customer names include the Dutch National Police, Rabobank and Statnett. Dustin's own security leadership has a place in the export too: both CISOs are listed below. But we are not only calling out Dustin Group with this post; we are calling out the duplicitous incident response firm they hired to negotiate with us, who we have reason to believe lied not only to us, but to Dustin as well. Because we are not 100% certain of which firm this is (merely 95% or so), we will refrain from calling them out by name. But othe…
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

