Ransomware victim disclosure
← All victimsRIECO Industries Limited
Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- India
- Sector
- Manufacturing
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileRIECO Industries Limited is an India-based engineering company that designs and manufactures equipment and systems for bulk solid handling, air pollution control, grinding, pneumatic conveying, and mixing. The company serves a broad range of industries including cement, pharma, food, petrochemical, steel, and agro-chemical sectors. It also offers project engineering services and after-market support such as AMC and retrofitting solutions.
- Industry
- Industrial Engineering Equipment & Bulk Solids Processing
Attack summary
Severity: high — Engineering drawing data for an industrial equipment manufacturer constitutes significant proprietary and potentially sensitive business data (design IP, manufacturing specifications). Confirmed exfiltration with data published elevates severity; while not directly regulated PII at scale, the publication of technical drawings can have serious competitive and operational security implications.The Nightspire ransomware group claims to have exfiltrated data from RIECO Industries Limited, with the leak post referencing drawing data as part of the disclosed material. The disclosed status is listed as data_published, indicating the group has published at least some stolen data.
Data the group says was taken
AI dossier — extracted from the leak post- Engineering drawing data
What the group claims
drawing data
Sources
- Victim sitewww.rieco.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

