Ransomware victim disclosure
← All victimsWiBeats S.r.l.
listed as wibeats.it · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Italy
- Sector
- Technology
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileWiBeats S.r.l. is an independent asset management and loans service group based in Turin, Italy, highly specialised in the selection and management of distressed assets. The company offers services including property management, REOCO consulting, leasing, and BIM management, and operates subsidiary companies such as BFORMS, WIBITA, and WIMOVE. It has been active for at least ten years and has received coverage in major Italian financial and business media.
- Industry
- Asset Management & Real Estate Loan Services
- Address
- Via Sant'Agostino 8, 10122 Torino (TO), Italy
Attack summary
Severity: critical — WiBeats operates in asset management and loan services, meaning exfiltrated data is highly likely to include regulated financial data, client PII, and sensitive contractual/loan records. Data has been confirmed published ('data_published'), indicating actual exfiltration and release of sensitive financial sector information.LockBit 5 claims to have attacked WiBeats S.r.l. and the disclosure status indicates data has been published, suggesting exfiltration and likely publication of company data. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Asset management records
- Loan and financial services data
- Property management documents
- Corporate business data
- Potentially client financial information
What the group claims
WIBEATS is an independent Asset Management and Loans Service groups, highly specialised in the selec...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

