Ransomware victim disclosure
← All victimsFondonorma
listed as fondonorma.org.ve · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Venezuela
- Sector
- Financial Services
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileFondonorma is Venezuela's national standards body, with over 50 years of operation dedicated to developing quality standards, certifying management systems, products and persons, and training professionals. It serves businesses across Venezuela by helping them demonstrate compliance with national and international quality and safety requirements. The organization also conducts public consultations on technical norms and operates technical committees.
- Industry
- Standards, Certification & Quality Assurance
Attack summary
Severity: high — Data is confirmed as published by the ransomware group, indicating exfiltration of what is likely business-sensitive and potentially regulated data from a national standards and certification body. While no specific volume is stated, the nature of the organization means client business records and certification data are at risk.LockBit 5 claims to have attacked Fondonorma and the disclosure status indicates data has been published, suggesting exfiltration of company data. No specific ransom amount or data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Certification records
- Business client data
- Management system documentation
- Professional training records
- Internal organizational documents
What the group claims
Fondonorma is a Venezuelan certification company that helps businesses prove they meet quality and s...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

