Ransomware victim disclosure
← All victimsCFTC Metallurgie
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- France
- Sector
- Manufacturing
- Listed on leak site
- Mar 14, 2026
About the victim
AI dossier — public-source company profileCFTC Métallurgie is the metallurgy sector branch of the CFTC (Confédération Française des Travailleurs Chrétiens), a French Christian trade union confederation. It represents workers in the metallurgy and metalworking industries in France, providing union membership services, rights information, and workplace representation. The organisation operates a member portal and partners with benefits providers such as Swile.
- Industry
- Metallurgy & Industrial Trade Union Services
Attack summary
Severity: high — The disclosed status is 'data_published', indicating data has been exfiltrated and released. As a trade union, the organisation likely holds sensitive PII of members (workers), including employment details, union membership records, and potentially financial/benefits data, representing significant personal data exposure even without confirmed volume.The Nightspire ransomware group claims to have attacked CFTC Métallurgie and lists the disclosure status as data_published, suggesting exfiltration and/or publication of data; however, the leak post content is currently unavailable, so specific claims about encryption or exfiltration cannot be verified from the post itself.
What the group claims
Data is not available now.
Sources
- Victim sitewww.cftc-metallurgie.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

