Ransomware victim disclosure
← All victimsFerretti Construction
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Italy
- Sector
- Construction
- Listed on leak site
- Feb 2, 2026
- Data size
- 66 GB
About the victim
AI dossier — public-source company profileFerretti Construction is an Italian engineering and construction company with approximately 100 years of operating history. The company provides services spanning basic and detail engineering, construction execution, and project and construction management. Its focus is on industrial construction projects.
- Industry
- Industrial Engineering & Construction
Attack summary
Severity: critical — Confirmed exfiltration of 66 GB including regulated PII (passports, driving licences) at employee scale, financial records, and sensitive contractual documents; data is stated as pending publication, representing imminent large-scale regulated-data exposure.Akira claims to have exfiltrated approximately 66 GB of corporate data from Ferretti Construction, including detailed employee identity documents, financial records, confidentiality agreements, contracts, NDAs, and project files, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driving licences
- Financial records
- Confidentiality agreements
- Contracts and agreements
- NDAs
- Project files
What the group claims
Ferretti Construction is an Italian Engineering & Construction Co mpany with a track record of 100 years in the field of industria l construction. They provide services from basic & detail enginee ring, to construction as well as project and construction managem ent. We will upload 66gb of corporate data soon. Detailed employee inf ormation (passports, DLs and so on), financials, confidentiality agreements, contracts and agreements, lots of project files, NDAs , etc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

