Ransomware victim disclosure
← All victimsThialf
Claimed by Thegentlemen · listed 6 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Netherlands
- Sector
- Energy & Utilities
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileThialf is a world-renowned ice arena in Heerenveen, Netherlands, serving as the home base for the Dutch national speed skating team. It hosts elite competitions in long-track and short-track speed skating, figure skating, and ice hockey, and has been confirmed as the long-track speed skating venue for the 2030 Winter Olympics. The facility also offers public recreational skating and corporate event services.
- Industry
- Sports & Recreation Facilities
- Address
- Heerenveen, Netherlands
Attack summary
Severity: low — The leak post contains only general description of the company with no evidence of data exfiltration, proof files, or operational impact. No ransom demand or specific data types are mentioned. This appears to be a listing/announcement without substantive proof.The group claims to have conducted an attack on Thialf, with the leak post published on a data disclosure platform. No specific details are provided regarding what data was exfiltrated or whether encryption occurred.
What the group claims
***.nl zoominfo.com/c/thialf/430686423 Thialf is a world-renowned ice arena located in Heerenveen, Netherlands, often referred to as the "Cathedral of Speed Skating." It serves as the home base for the Dutch national speed skating team and hosts a wide range of ice sports, including long track and short track speed skating, figure skating, and ice hockey. Recently, it was officially confirmed as the long-track speed skating venue for the 2030 Winter Olympics. The facility is celebrated for its modern, sustainable design and its role as a major hub for both elite professional competitions and public recreational skating.
Sources
- Victim sitethialf.nl
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

