Ransomware victim disclosure
← All victimsНартис (Nartis)
listed as nartis.ru · Claimed by Warlock · listed 7 months ago
Status timeline
- ListedNov 6, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNartis (Нартис) is a leading Russian manufacturer of intelligent measurement, control, and radio-electronic devices, headquartered in Cherepovets, Vologda Oblast. The company produces smart electricity, water, and gas meters, EV charging stations, communication modules, microcontrollers, and data collection equipment. With 11,000 m² of production space and a capacity of 2.5 million metering devices per year, Nartis serves the national energy infrastructure modernisation market and is part of the NEK Group.
- Industry
- Intelligent Metering & Power Electronics Manufacturing
- Address
- Вологодская область, г. Череповец, Северное шоссе, 40В (Cherepovets, Vologda Oblast, Severnoye Shosse 40V, Russia)
- Employees
- 950
Attack summary
Severity: medium — Data is marked as published by the group, indicating some level of confirmed disclosure. However, no details on data type, volume, or sensitivity are provided in the leak post, and no specific proof artifacts are described. The victim is a critical infrastructure-adjacent manufacturer (smart metering for energy grid), which elevates concern above low.The Warlock ransomware group has listed Nartis under a 'data_published' disclosure status, indicating data has been published. No description of the attack method (encryption, exfiltration, or both) or the specific data claimed was provided in the leak post.
What the group claims
No description provided.
Sources
- Victim sitenartis.ru
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

