Ransomware victim disclosure
← All victimsNeinver
Claimed by Ransomhouse · listed 3 months ago
Status timeline
- Listed
Feb 27, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- Spain
- Sector
- Not Found
- Listed on leak site
- Feb 27, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileNEINVER is Europe's second-largest outlet centre operator, managing 15 centres totalling 311,600 sqm of gross leasable area under The Style Outlets and FACTORY brands. The company oversees 500,000 sqm of retail space across approximately 2,000 stores and more than 900 premium brands in six European countries. With 45 years of experience, NEINVER specialises in development, asset management and fund management of retail property.
- Industry
- Commercial Real Estate & Outlet Centre Management
- Address
- Spain (headquarters; operates across Spain, Italy, France, Germany, Portugal and Poland)
- Employees
- 350
Attack summary
Severity: high — Confirmed encryption of a large European commercial real estate operator with 743 GB of data reportedly at stake, significant business and tenant data exposure, and cross-border operational scope across six countries. Data not yet published but evidence status claimed.RansomHouse claims to have encrypted systems at NEINVER and lists the case with a status of 'EVIDENCE', indicating proof has been collected but data has not yet been formally published. The disclosed data size associated with a concurrent listing in the same post references 743 GB, though the ransom figure stated is $740.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial records
- Asset and fund management documents
- Retail tenant and brand partner data
- Employee records
- Operational property management data
What the group claims
NEINVER is Europe’s second-largest outlet centre operator (ICSC 2012), managing 15 centres totaling 311,600 sqm of GLA under The Style Outlets and FACTORY brands. Recognized by leading international brands as the second most trusted outlet manager (Ecostra-Magdus 2013), the company oversees 500,000 sqm of retail space, 2,000 stores and more than 900 premium brands across Spain, Italy, France, Germany, Portugal and Poland. With 45 years of experience, NEINVER is a leading international property company specializing in development, asset management and fund management.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
