Ransomware victim disclosure
← All victimsIsoledil
listed as isoledilcappotti.it · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileIsoledil is an Italian construction services company based in Castiglione delle Stiviere (Mantova), operating across northern Italy including Brescia, Verona, Cremona, and the Lake Garda area. The company specialises in thermal and acoustic insulation, thermal cladding systems (cappotti termici), blown-in insulation (insufflaggio), plastering, drywall works, painting, and roofing. It is led by Dimitri and employs a qualified workforce serving both residential and commercial clients.
- Industry
- Building Insulation & Construction Services
- Address
- Via Giuseppe Verdi, 46A, 46043 Castiglione delle Stiviere (MN), Italy
Attack summary
Severity: medium — Data has been published by the group, indicating confirmed exfiltration, but the victim is a small regional construction SME with no indication of large-scale regulated PII (medical, financial, government) exposure; scale and sensitivity of leaked data are unknown.LockBit 5 claims to have attacked Isoledil and has published data (disclosed status: data_published), suggesting exfiltration of company data. The leak post provides no detail on the volume or specific categories of data exposed.
Data the group says was taken
AI dossier — extracted from the leak post- Company business data
- Potentially client/customer records
- Potentially financial/invoicing documents
- Potentially employee information
What the group claims
La professionalità al Vostro servizio ISOLEDIL una garanzia di qualità ed esperienza... Grazie...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

