Ransomware victim disclosure
← All victimsVODAFONE
Claimed by lapsus$ · listed 5 days ago
Status timeline
- Listed
May 29, 2026
- Data leaked
At a glance
- Group
- lapsus$
- Status
- Data leaked
- Country
- DE
- Sector
- Telecommunication
- Listed on leak site
- May 29, 2026
About the victim
AI dossier — public-source company profileVodafone is one of the largest telecommunications companies in Europe and Africa, operating consumer and business services across dozens of markets. The company provides mobile, broadband, and digital services to millions of customers globally.
- Industry
- Telecommunications
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive operational and development data including infrastructure, source code, and network topology from a major global telecommunications provider. This enables potential follow-on attacks and infrastructure compromise at massive scale.LAPSUS$ claims to have exfiltrated Vodafone's full infrastructure, source code, GitHub repositories, and internal network maps. No ransom demand is stated; data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Full infrastructure documentation
- Source code repositories
- GitHub tree/development assets
- Internal network maps
What the group claims
Full Infrastructure, Source Code, GitHub Tree & Internal Network Maps
Sources
- Victim sitevodafone.com
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
