Ransomware victim disclosure
← All victimsECOVACS
Claimed by Spacebears · listed 6 hours ago
Status timeline
- ListedJun 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Spacebears
- Status
- Data leaked
- Country
- China
- Sector
- Consumer Services
- Listed on leak site
- Jun 16, 2026
About the victim
AI dossier — public-source company profileECOVACS is a Chinese robotics company founded in 1998 in Suzhou, specializing in smart home cleaning solutions. The company manufactures and sells robot vacuums (DEEBOT), window cleaners (WINBOT), robotic lawn mowers (GOAT), and pool cleaning robots (ULTRAMARINE) in over 145 countries with tens of millions of users globally.
- Industry
- Consumer Robotics & Smart Home Cleaning Devices
- Address
- Suzhou, China
- Founded
- 1998
Attack summary
Severity: high — Confirmed exfiltration of 2 TB of data from a major global consumer robotics company with tens of millions of users. Data scope unspecified but scale and operational reach suggest significant exposure potential (likely including customer/user information).The spacebears group claims to have exfiltrated approximately 2 TB of data from ECOVACS. The leak post does not specify the nature of the compromised data or whether encryption occurred.
Data the group says was taken
AI dossier — extracted from the leak post- company data (unspecified)
What the group claims
ECOVACS is a highly successful Chinese robotics company founded in 1998 in Suzhou. It has grown into a global leader in smart home cleaning solutions, with its products sold in over 145 countries and trusted by tens of millions of users worldwide.The company is best known for its award-winning DEEBOT robot vacuums, WINBOT window cleaners, GOAT robotic lawn mowers, and other intelligent cleaning devices powered by advanced AI and navigation technologies.Driven by the vision “Robotics for All”, ECOVACS continues to innovate and expand rapidly, making premium home robotics accessible and effective for everyday consumers.About 2 TB of stolen data. https://www.***.com/
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

