Ransomware victim disclosure
← All victimsSirl
Claimed by Thegentlemen · listed 6 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Portugal
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileSIRL is a Portuguese manufacturing company headquartered in Penela, Coimbra, specializing in production and distribution of machinery and tools for the civil construction industry. The company manufactures concrete mixers, construction equipment, and welding tools, serving the European construction machinery sector with 51–200 employees.
- Industry
- Construction Machinery & Equipment Manufacturing
- Address
- Penela, Coimbra, Portugal
- Employees
- 51-200
- Founded
- 1988
Attack summary
Severity: medium — Data has been published by the ransomware group, indicating successful exfiltration. However, no specific sensitive data categories (PII at scale, financial records, customer lists, trade secrets) are detailed in the post, and the disclosed information is largely publicly available from the company website.The threat actor claims to have accessed and published data from SIRL. The post does not explicitly state whether encryption or exfiltration occurred, but the 'data_published' status indicates exfiltration of company records.
Data the group says was taken
AI dossier — extracted from the leak post- Company business records
- Operational data
What the group claims
***.pt zoominfo.com/c/sirl/372746430 Portuguese manufacturing company founded in 1988 and headquartered in Penela, Coimbra. It specializes in producing and selling machinery and tools for the civil construction industry.Their flagship products are concrete mixers, complemented by various other construction equipment and welding tools. The company employs 51–200 people and is a recognized supplier in the European construction machinery sector
Sources
- Victim sitesirl.pt
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

