Ransomware victim disclosure
← All victimsKontact Consortium India Pvt
Claimed by Thegentlemen · listed 4 hours ago
Status timeline
- ListedJul 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- India
- Listed on leak site
- Jul 30, 2026
About the victim
AI dossier — public-source company profileKontact Consortium India Pvt Ltd is an Indian engineering company with over 50 years of experience specializing in electrical and mechanical solutions for railways, infrastructure, and industrial sectors. They operate a 40,000+ sq. ft. manufacturing facility and provide end-to-end services including railway rolling stock supplies, LV/MV power distribution panels, and electrical contracting, serving major clients including ISRO, Tata Projects, and DMRC.
- Industry
- Electrical & Mechanical Engineering for Railways & Infrastructure
- Employees
- 51-200
Attack summary
Severity: medium — The victim is a critical infrastructure supplier (railways, ISRO projects) but the leak post provides no evidence of data exfiltration, proof files, or operational disruption. Classification as medium due to the sensitive nature of infrastructure sector involvement and lack of transparency about breach scope.The ransomware group claims to have compromised Kontact Consortium India Pvt Ltd. The post does not specify whether data was exfiltrated, encrypted, or both, nor does it detail what specific data categories are at stake.
What the group claims
kontact.in zoominfo.com/c/kontact-consortium-india-pvt-ltd/437934184 Kontact is an Indian engineering company with over 50 years of experience, specializing in electrical and mechanical solutions for the railway, infrastructure, and industrial sectors. They provide end-to-end services, including railway rolling stock supplies, LV/MV power distribution panels, and electrical contracting, backed by a 40,000+ sq. ft. manufacturing facility. The company is recognized for its reliability and quality, holding key international certifications such as ISO 9001, IRIS, and EN 15085-2
Sources
- Victim sitekontact.in
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

