Ransomware victim disclosure
← All victimsiSMA CONTROLLI
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Poland
- Sector
- Manufacturing
- Listed on leak site
- Feb 16, 2026
About the victim
AI dossier — public-source company profileiSMA CONTROLLI S.p.A. is a manufacturer specializing in building management system (BMS) components and solutions, including valves, actuators, sensors, controllers, and software. The company is based in Italy (indicated by the S.p.A. legal form) and serves the building automation sector. Their products are used for environmental control and energy management in commercial and industrial buildings.
- Industry
- Building Management Systems & HVAC Controls
Attack summary
Severity: medium — Exfiltration of client files and project specifications is claimed but data has not yet been published and no proof files have been shared; the threatened disclosure of client and project data elevates this above low, but absence of confirmed regulated/sensitive data (e.g. PII at scale, financial, medical) and lack of published proof keep it at medium.Akira claims to have exfiltrated corporate data from iSMA CONTROLLI S.p.A. and states they will publish client files, project documents, specifications, and other data imminently; no encryption claim is explicitly stated.
Data the group says was taken
AI dossier — extracted from the leak post- Client files
- Project documents
- Technical specifications
- Corporate data
What the group claims
iSMA CONTROLLI S.p.A. specializes in providing a wide range of pr oducts including valves, actuators, sensors, controllers, and sof tware solutions for building management systems. We will upload corporate data soon. Clients' files, projects and specifications and other data.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

