Ransomware victim disclosure
← All victimsCSA SpA
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCSA S.p.A. is an Italian company providing products and services to the shipping industry, including ship services, liner agency, and logistics. The company emphasises safety and customer satisfaction and operates to international standards. Based in Italy, it serves clients in the maritime and shipping sector.
- Industry
- Shipping & Maritime Services
Attack summary
Severity: high — Confirmed exfiltration of ~10 GB including PII (employee personal data), financial records, and client files constitutes significant business and personal data exposure; data published status indicates imminent or actual release.Akira claims to have exfiltrated approximately 10 GB of corporate data from CSA S.p.A., including employee personal data, financial records, contracts and agreements, client files, and other internal documents, with publication described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal data
- Financial records
- Contracts and agreements
- Client files
- Internal corporate documents
What the group claims
CSA S.p.A. is a company that provides a broad range of quality pr oducts and services tailored to the shipping industry, emphasizin g safety and customer satisfaction. Their offerings include ship services, liner agency, and logistics, all designed to meet the h ighest international standards. We will upload 10gb of corporate data soon. Personal data of empl oyees, financials, contracts and agreements, client files, and a lot of other internal files.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

