Ransomware victim disclosure
← All victimsBK Group
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Netherlands
- Listed on leak site
- Mar 4, 2026
- Data size
- 89 GB
About the victim
AI dossier — public-source company profileBK Group is described as a leading general contractor in Europe specialising in interior construction and technical facility management. The company is involved in planning, building, and maintaining projects across sectors including retail, fitness, and automotive. It is registered in the Netherlands.
- Industry
- Interior Construction & Technical Facility Management
Attack summary
Severity: critical — The exfiltrated dataset includes government-issued identity documents (passports, driver's licences, national IDs) constituting regulated PII at scale, alongside financial and confidential business data totalling 89 GB, with data publication confirmed as imminent.Akira claims to have exfiltrated 89 GB of corporate data from BK Group, including employee personal identity documents, NDAs, contracts, financial records, and confidential project files, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licences
- German national ID documents
- NDAs
- Contracts and agreements
- Financial records
- International project files
- Confidential corporate files
What the group claims
bk Group is the leading general contractor in Europe for interior construction and technical facility management. They specialize in planning, building, and maintaining various types of projects, including retail stores, fitness centers, and automotive buildin gs. We will upload 89gb of corporate data soon. Employee personal fil es (passports, DLs, German IDs and so on), NDAs, contracts and ag reements, financials, international projects, confidential files, and so on.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

