Ransomware victim disclosure
← All victimsMabetex Group
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Construction
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileMabetex Group is a Swiss-based firm established as a leader in design, construction, and project engineering, specialising in administrative and governmental buildings as well as facilities in the health, sport, and tourism sectors, including hospitals, stadiums, and hotels. The company operates internationally, delivering large-scale public and institutional construction projects across multiple countries.
- Industry
- Design, Construction & Project Engineering of Government & Public Buildings
Attack summary
Severity: high — The threat actor claims exfiltration of 42 GB of data that includes regulated PII (passports and identity documents), detailed financial records, and sensitive client and project data related to governmental and public-sector construction; however, data has not yet been fully published and no confirmed download is available, placing this at high rather than critical.Akira claims to have exfiltrated approximately 42 GB of corporate data from Mabetex Group, including employee files with passports and identity documents, detailed financials, client information, and documentation related to international projects; the data is described as forthcoming for publication.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports and identity documents
- Employee files
- International project documentation
- Detailed financial records
- Client information
What the group claims
Mabetex Group has established itself as a leader in design, const ruction and project engineering of administrative and governmenta l buildings as well as buildings in the health, sport and tourism sector, like hospitals, stadiums, hotels. We will upload 42gb of corporate data soon. Employee files (passp orts and other docs), lots of documents about international proje cts, detailed financials, client information, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

