Ransomware victim disclosure
← All victimsSirsa S.p.A.
listed as sirsa.it · Claimed by Lockbit5 · listed 6 hours ago
Status timeline
- ListedAug 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Italy
- Sector
- Technology
- Listed on leak site
- Aug 3, 2026
About the victim
AI dossier — public-source company profileSirsa S.p.A. is an Italian family-run manufacturer specializing in plastic processing, injection molding, and blow molding. With over 50 years of international market presence, the company serves the home, leisure, garden, and industrial sectors through an R&D-driven approach to custom solutions. Operations span three production facilities in northern Italy with proprietary product lines and partnerships with international clients.
- Industry
- Plastic Processing & Injection Molding
- Address
- Via Veneto, 7, Palazzolo sull'Oglio (BS), Italy; with additional sites in Capriolo (BS) and Oggiono (LC)
Attack summary
Severity: high — Confirmed data exfiltration and public disclosure by established ransomware group (LockBit5) of a manufacturing company's operational and business data. While regulated/sensitive data categories are not explicitly confirmed, the breadth of business information at risk and public exposure justifies 'high' severity.LockBit5 claims to have breached Sirsa and exfiltrated company data. The group has published data as disclosed status indicates 'data_published', but specific details on data types and exfiltration method are not provided in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- proprietary product information
- customer data
- operational/technical documentation
What the group claims
SIRSA operates in the field of processing and molding plastic materials, offering concrete, safe, an...
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

