Ransomware victim disclosure
← All victimsRamet-Trom
listed as http://ramet-trom.co.il/ · Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMar 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Israel
- Sector
- Manufacturing
- Listed on leak site
- Mar 1, 2026
- Data size
- 1 TB
About the victim
AI dossier — public-source company profileRamet-Trom (ramet-trom.co.il) is an Israeli company operating in the manufacturing sector, likely supplying industrial or defense-related components based on the domain and the attacker's reference to the Israeli Ministry of Defense. No public site content was available to confirm additional details about their products or scale.
- Industry
- Defense & Industrial Manufacturing
Attack summary
Severity: critical — 1 TB of confirmed exfiltrated and published data including blueprints and contracts from a company with apparent defense-sector ties constitutes a critical disclosure of sensitive industrial and potentially defense-related intellectual property at significant scale.The Incransom group claims to have exfiltrated approximately 1 TB of data including blueprints, contracts, and other documents, and has published the data; the post includes a politically motivated reference to the Israeli Ministry of Defense.
Data the group says was taken
AI dossier — extracted from the leak post- Blueprints / technical drawings
- Contracts
- Unspecified additional business documents
What the group claims
1 terabyte of data, blueprints, contracts and much more, not recognized by the israeli ministry of defense as a terrorist organization.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

