Ransomware victim disclosure
← All victimsAdriatic Port Authority
Claimed by Anubis · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Anubis
- Status
- Data leaked
- Country
- Italy
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profileAdriatic Port Authority is an Italian governmental or quasi-governmental body responsible for the administration, regulation, and management of one or more ports along the Adriatic coast of Italy. Port authorities in Italy oversee maritime traffic, port infrastructure, customs coordination, and logistics operations. The specific port or ports under this authority's jurisdiction cannot be confirmed from the available information.
- Industry
- Port Authority & Maritime Transportation
Attack summary
Severity: high — The victim is an Italian port authority — a critical infrastructure entity in the transportation/logistics sector. The disclosed status is 'data_published', confirming actual data exfiltration rather than a mere listing. Port authorities handle sensitive operational, logistical, personnel, and potentially government-classified data. Disruption or exposure of such data poses significant national and economic security implications, warranting a 'high' rating; 'critical' is not assigned due to lackThe Anubis ransomware group claims to have attacked Adriatic Port Authority and has published data (disclosed status: data_published), suggesting exfiltration of organizational data, though the leak post provides minimal detail on the nature or volume of the data involved.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified organizational data
What the group claims
www.porto.ancona.it - data breach.
The leak post
captured from the group's siteAnubis blog ANUBIS NEWS FAQ ABOUT RULES English English Español Русский 中文 Deutsch Description Micaforce Technology Download
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

