Ransomware victim disclosure
← All victimsWEDA ROBOTICS
Claimed by lamashtu · listed 1 month ago
Status timeline
- Listed
Apr 14, 2026
- Data leaked
At a glance
- Group
- lamashtu
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileWEDA Robotics is a Swedish manufacturer of remotely operated, fully submerged robotic cleaning systems for tanks, reservoirs, lagoons, and other water infrastructure. Founded on over 100 years of engineering heritage dating to mechanical pool cleaners in the 1920s, the company serves industries including wastewater, mining, oil & gas, aquaculture, and municipal infrastructure across 40+ countries on 5 continents. Its headquarters and postal address are located in Södertälje, Sweden.
- Industry
- Industrial Robotics & Automated Cleaning Systems
- Address
- Wedavägen 4a, SE-152 42 Södertälje, Sweden
Attack summary
Severity: high — Data has been confirmed as published by the threat actor, indicating successful exfiltration of business data from an internationally operating industrial robotics company with customers across critical infrastructure sectors (wastewater, oil & gas, power, municipal); the breadth of sensitive operational and customer data at risk elevates this beyond medium.The ransomware group Lamashtu claims to have attacked WEDA Robotics and has published data (disclosed status: data_published), though no specific ransom amount or data volume was stated. The leak post references the company's history and global operations, suggesting exfiltration of internal company data.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company documents
- Business operations data
- Potentially customer/distributor records
What the group claims
Over 100 Years of Engineering. Now Pioneering the Future of Sustainable Cleaning. From mechanical pool cleaners in the 1920s to submerged, no drain robotic systems used across 40+ countries.
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
