Ransomware victim disclosure
← All victimsCTI BAT
listed as cti-bat.fr · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCTI BAT is a French construction company specialising in aluminium joinery (menuiserie aluminium), metal framework (charpente métallique), and metalwork/locksmithing (métallerie-serrurerie). The company operates production workshops totalling approximately 2,000 m² plus 450 m² of offices. It undertakes building projects including public facilities such as schools.
- Industry
- Building & Construction – Aluminium Joinery, Steel Framing & Metalwork
Attack summary
Severity: high — Data has been published (data_published status) by the ransomware group, confirming exfiltration and public release of business data, even though the specific data categories and volume are not fully enumerated in the available excerpt.LockBit 5 claims to have attacked CTI BAT and has published data (disclosed status: data_published), indicating exfiltration of company data, though the specific volume and nature of the exfiltrated files are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Company business data
- Potentially internal documents
What the group claims
THE COMPANY The company CTI BAT is a building company specialized in the sectors of activity: a...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

