Ransomware victim disclosure
← All victimsINGKA GROUP
Claimed by Lapsus$ · listed 6 hours ago
Status timeline
- ListedJun 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Lapsus$
- Status
- Data leaked
- Country
- Sweden
- Sector
- Consumer Services
- Listed on leak site
- Jun 13, 2026
About the victim
AI dossier — public-source company profileIngka Group is the operating company behind the IKEA brand, operating 411 IKEA stores and 209 additional formats across 32 countries, along with 37 shopping centres in 14 countries and multiple investment divisions. The group is driven by the IKEA vision to provide affordable home furnishing solutions globally.
- Industry
- Furniture Retail & Real Estate
Attack summary
Severity: high — Confirmed exfiltration of significant operational and strategic business data including cloud infrastructure, e-commerce systems, and supply chain logistics for a global Fortune 500 retailer. Publication of such data poses operational and competitive risk despite lack of regulated PII emphasis in the disclosed summary.Lapsus$ claims to have exfiltrated full mapping of Ingka Group's global e-commerce architecture, internal coworker platforms, supply chain logistics, cloud infrastructure, and AI/MLOps repositories. Data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- e-commerce architecture documentation
- internal coworker platforms
- supply chain logistics
- cloud infrastructure specifications
- AI/MLOps repositories
What the group claims
Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories
Sources
- Victim siteingka.com
- Leak posthttps://anonfilesnew.com/s/MhMoAjUKPeJ
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

