Ransomware victim disclosure
← All victimsbun.nl
Claimed by Threeam · listed 3 months ago
Status timeline
- ListedMay 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Netherlands
- Listed on leak site
- May 1, 2026
About the victim
AI dossier — public-source company profileBun Holding (bun.nl) is a Dutch holding company operating three divisions: real estate (vastgoed), property development (projectontwikkeling), and supermarkets. The company develops and renovates residential and commercial properties across multiple Dutch cities and is one of the largest Albert Heijn franchise operators in the Netherlands. It manages a portfolio of rental homes, commercial spaces, and garages while also running several Albert Heijn supermarket locations.
- Industry
- Real Estate Development & Property Management
- Address
- Netherlands (multiple cities including Almere, Apeldoorn, Goirle, Groningen, Tiel, Hilversum, Kampen)
Attack summary
Severity: high — Data has been confirmed published by the threat actor, indicating exfiltration of significant business data including tenant PII, real estate records, and potentially financial/contractual documents across a multi-division holding company. Publication without a stated ransom suggests the exfiltration phase is complete.The ThreeAM ransomware group claims to have attacked Bun Holding and has published data (disclosed status: data_published), suggesting both exfiltration and likely encryption occurred. No specific ransom amount or data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business records
- Real estate portfolio data
- Tenant/rental records
- Supermarket franchise operational data
- Employee/HR records (inferred from Bun Academy and vacancies)
- Financial and contractual documents
What the group claims
Bun creëert woon-, werk- en leefruimte voor iedereen en van de beste kwaliteit. Wij spelen in op zaken die leven in de maatschappij. De behoefte hierin aan woningen in is groot. Daarom houden wij ons bezig met de ontwikkeling en het renoveren van
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

