Ransomware victim disclosure
← All victimsWilhelmsen
listed as wilhelmsen.com · Claimed by LockBit · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Norway
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileWilhelmsen is a global maritime industry group founded in Norway in 1861, operating one of the world's largest maritime networks. The company provides ship management, marine products, logistics, and port services across a worldwide footprint. It serves thousands of vessels and customers across the global shipping industry.
- Industry
- Maritime Shipping & Logistics
- Address
- Strandveien 20, 1366 Lysaker, Norway
- Employees
- 10000+
- Founded
- 1861
Attack summary
Severity: high — Data has been confirmed as published by LockBit against a major global maritime logistics group, indicating confirmed exfiltration of significant business data from a critical transportation and logistics operator with worldwide scale.LockBit claims to have compromised Wilhelmsen and has published data (disclosed status: data_published), indicating exfiltration of company data. No specific ransom amount was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Internal documents
- Potentially employee records
- Potentially client/customer records
- Operational/logistics data
What the group claims
Founded in Norway in 1861, Wilhelmsen is a global maritime industry group. With the world's lar...
Sources
- Victim sitewilhelmsen.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

