Ransomware victim disclosure
← All victimsbun.nl
Claimed by threeam · listed 20 days ago
Status timeline
- Listed
May 1, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileBun Holding (bun.nl) is a Dutch holding company operating three divisions: real estate (vastgoed), property development (projectontwikkeling), and supermarkets. The company develops and renovates residential and commercial properties across multiple Dutch cities and is one of the largest Albert Heijn franchise operators in the Netherlands. It manages a portfolio of rental homes, commercial spaces, and garages while also running several Albert Heijn supermarket locations.
- Industry
- Real Estate Development & Property Management
- Address
- Netherlands (multiple cities including Almere, Apeldoorn, Goirle, Groningen, Tiel, Hilversum, Kampen)
Attack summary
Severity: high — Data has been confirmed published by the threat actor, indicating exfiltration of significant business data including tenant PII, real estate records, and potentially financial/contractual documents across a multi-division holding company. Publication without a stated ransom suggests the exfiltration phase is complete.The ThreeAM ransomware group claims to have attacked Bun Holding and has published data (disclosed status: data_published), suggesting both exfiltration and likely encryption occurred. No specific ransom amount or data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business records
- Real estate portfolio data
- Tenant/rental records
- Supermarket franchise operational data
- Employee/HR records (inferred from Bun Academy and vacancies)
- Financial and contractual documents
What the group claims
Bun creëert woon-, werk- en leefruimte voor iedereen en van de beste kwaliteit. Wij spelen in op zaken die leven in de maatschappij. De behoefte hierin aan woningen in is groot. Daarom houden wij ons bezig met de ontwikkeling en het renoveren van
Sources
Source
Indexed 20 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
