Ransomware victim disclosure
← All victimsSIT Group / Robusta
Claimed by Bavacai · listed 15 days ago
Status timeline
- Listed
May 5, 2026
- Data leaked
At a glance
- Group
- Bavacai
- Status
- Data leaked
- Country
- IT
- Sector
- Business Services
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileSIT Group is an Italian company operating under the domain sitgroup.it, active in the business services sector. The leak post also associates it with Robusta, a Bulgarian entity (robusta.bg), suggesting a cross-border operational or corporate relationship. No further verifiable details about their specific services or scale are available from the provided sources.
- Industry
- Business Services
Attack summary
Severity: medium — Data has been published (disclosed status: data_published) indicating confirmed exfiltration, but the post provides very limited detail on the nature, volume, or sensitivity of the data; no regulated PII at scale, medical, financial, or government data is confirmed.The Bavacai ransomware group claims to have compromised SIT Group and its associated Bulgarian entity Robusta, with data published including what appears to be email account data from the abv.bg domain. The disclosed status indicates data has been published, though no specific data volume or encryption claim is detailed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Email accounts (abv.bg)
- Corporate data from SIT Group
- Corporate data from Robusta (Bulgaria)
What the group claims
Italian company SIT Group (sitgroup.it) and Bulgarian Robusta (robusta.bg). Also abv.bg emails.
The leak post
captured from the group's siteFile Manager File Manager home page BARAAAI Data is being prepared for publication. BAPAMAI Data is being prepared for publication. BAUARAI Data is being prepared for publication. BAVADAI Data is being prepared for publication. BAVACAI Data is being prepared for publication. BAVAQAI Data is being prepared for publication. Raycolighting DEMO 3137 S Alameda Street, Los Angeles, CA 90058, USA $10 000 Organization with 2 emails extracted. Domain: raycolighting.com baralai Data is being prepared for publication. CEAGESP / Netfeirasp DEMO São Paulo, Brazil $20 000 Brazilian produce wholesale market network. Domain netfeirasp.ceagesp (CEAGESP). Also demarchibrasil.com.br accounts. Colegio María Inmaculada (CMI) DEMO Moravia, San José, Costa Rica $50000 Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2. Académie de Montpellier / CSJM DEMO Béziers, Occitanie, France $15000 French public school network. Domain CSJM.BEZIERS, part of Académie de Montpellier (ac-montpellier.fr). Occitanie region (laregion.fr). Teacher and admin staff credentials. Palmers Relocations DEMO Victoria, Australia $63 000 Australian …
Sources
Source
Indexed 15 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
