Skip to main content

Ransomware victim disclosure

All victims

Dustin Group AB

listed as Dustin Group · Claimed by Fulcrumsec · listed 2 days ago

1d
Age
since listed · data leaked

Status timeline

  1. ListedSep 11, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Sweden
Listed on leak site
Sep 11, 2026

About the victim

AI dossier — public-source company profile

Dustin Group AB is a Swedish IT reseller and distributor operating customer-facing portals (Skyportal) and procurement systems. The company serves major Nordic and European institutional customers including banks, police, healthcare systems, and energy providers across multiple countries.

Industry
IT Reseller & Distributor

Attack summary

Severity: critical — Confirmed exfiltration of large-scale regulated sensitive data: over 1 million customer identity records, 92 Swedish personal identity numbers (PII), financial data (IBANs, banking instructions, invoicing), CRM records on high-profile institutional customers in defense, policing, banking, and healthcare sectors, internal security assessments, and source code. The breach exposes data of Dutch National Police, Rabobank, Statnett, ABN AMRO, healthcare systems (Erasmus MC, UMCG, Radboud UMC) and oth

FulcrumSec claims exfiltration of 6.2 TB of data including 1,041 git repositories with 24.5 million lines of source code, customer identity records (1.05+ million accounts), Jira/Confluence archives, CRM data covering major institutional customers, product and finance databases, and security assessment documents. The group alleges the company hired an incident response firm previously used in a failed negotiation with FulcrumSec during the Novo Nordisk incident.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • 1,041 git repositories with full development history
  • 24.5 million lines of source code
  • 5 TB container images
  • 1,058,417 customer identity records (names, emails, account status)
  • Skyportal customer identity store
  • Internal directory and Azure infrastructure-as-code
  • 501,564 Jira issue and comment files (2019–Aug 2026)
  • Dynamics 365/Dataverse CRM (23,030 accounts, 27,761 contacts)
  • 2.77 GB SQL Server backup (product, finance, supplier data)
  • 92 Swedish personal identity numbers
  • 15 checksum-valid IBANs and banking instructions
  • Nine customer security assessment decks
  • Security incident playbooks and compliance documentation

Original description

AI-summarised, not from the leak post

Dustin Group is a Swedish technology reseller and IT solutions provider headquartered in Stockholm, Sweden. The company operates primarily in the Nordic and Benelux regions, offering hardware, software, and IT services to businesses and public sector organizations. Its product portfolio includes computers, networking equipment, and cloud solutions. Dustin serves both SMBs and large enterprises, positioning itself as a one-stop shop for IT procurement and digital transformation support.

The leak post

captured from the group's site
Dustin Group AB • IT Reseller • 6.2 TB total holdings
[TORRENTS AVAILABLE — SEE TABLE BELOW](http://4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion/dustin/#initial-release)
6.2 TB total holdings • 1,041 git repositories • 24.5 million lines of code • ~5 TB of container images • 1,058,417 named identity records • 501,564 Jira issue and comment files • 92 Swedish personal identity numbers • nine customer security assessments
Today we are making the Dustin Group breach public. We hold the source code behind its webshops and customer portal, its customer identity store, internal directory, Atlassian estate, CRM, product databases and finance integrations.
The customer names include the Dutch National Police, Rabobank and Statnett. Dustin's own security leadership has a place in the export too: both CISOs are listed below.
But we are not only calling out Dustin Group with this post; we are calling out the duplicitous incident response firm they hired to negotiate with us, who we have reason to believe lied not only to us, but to Dustin as well. Because we are not 100% certain of which firm this is (merely 95% or so), we will refrain from calling them out by name. But othe…

Sources

Source

Indexed 2 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About fulcrumsec

FulcrumSec is a recently emerged ransomware group that was first observed in May 2026, operating with apparent financial motivations based on their targeting patterns across multiple countries and high-value sectors. Given the recency of their emergence and limited public documentation, the group's specific country of origin and potential affiliations remain unclear, though their targeting of victims across the United States, India, Netherlands, Colombia, and Japan suggests either a geographically distributed operation or deliberate international scope rather than nation-state backing. The group has demonstrated a preference for targeting technology companies, business services firms, and healthcare organizations, with 21 documented victims indicating a selective approach focused on sectors likely to yield significant ransom payments due to operational dependencies and sensitive data holdings. Their attack methodology details remain largely undocumented in public threat intelligence reports from major security firms, though their sector targeting suggests sophisticated initial access capabilities given the typically robust security postures of technology and healthcare organizations. No major high-profile campaigns or significant law enforcement actions against FulcrumSec have been publicly reported by CISA, FBI, or leading cybersecurity researchers as of available intelligence. The group appears to remain active as of the most recent observations, though the limited public intelligence on their operations suggests they may be maintaining a relatively low profile compared to more established ransomware enterprises. The group has been linked to 27 public disclosures across our corpus. First observed on a leak site on May 1, 2026; most recent post September 11, 2026. The operation is currently active.

Timeline of this disclosure

  • September 11, 2026Dustin Group listed by fulcrumsec on the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Technology sector, which has 3,577 disclosures indexed across all operators we track. Geographically, Dustin Group is reported in Sweden, a country with 18 ransomware disclosures in our corpus.

If your organisation is affected

A listing by fulcrumsec means Dustin Group appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CERT-SE (Sweden), as required for your jurisdiction.
  • Monitor for the data appearing on fulcrumsec's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.