Ransomware victim disclosure
← All victimsCommune de Nandrin
listed as nandrin.be · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCommune de Nandrin is a Belgian municipal government located in the province of Liège, Wallonia. It provides a range of public services to residents including civil registration, urban planning, environment, social services, education, and local infrastructure. It operates as a local authority serving the Nandrin municipality.
- Industry
- Municipal Government
- Address
- Place Ovide Musin 1, 4550 Nandrin, Belgique
Attack summary
Severity: high — The victim is a municipal government with likely PII of residents (civil registration, population records, tax data) and the status is data_published, indicating confirmed exfiltration and public release of government data affecting citizens.The LockBit 5 ransomware group claims to have attacked Commune de Nandrin, with the disclosure status recorded as data_published, indicating that data has been published. The public site also references recent 'perturbations informatiques aux services communaux' (IT disruptions to municipal services), consistent with a ransomware incident.
Data the group says was taken
AI dossier — extracted from the leak post- Municipal administrative records
- Resident population and civil registration data
- Financial and tax records
- Urban planning documents
- Employee/HR records
- Local government communications
What the group claims
Nandrin (French pronunciation: [nɑ̃dʁɛ̃]) is a municipality of Wallonia located in the province of L...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

