Ransomware victim disclosure
← All victimsComoli Ferrari
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedMay 22, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- Italy
- Sector
- Business Services
- Listed on leak site
- May 22, 2023
About the victim
AI dossier — public-source company profileComoli Ferrari is an Italian distributor of integrated plant engineering solutions, specialising in electrical, hydrothermal, and sanitary systems. Founded in 1929, the company serves customers across home, building, industry, city, and marine segments with products spanning electrical panels, automation, home automation, security, lighting, HVAC, and cabling. It operates an extensive sales-point network across Italy and provides technical support, training, and consulting services through a broad partner ecosystem.
- Industry
- Electrical & Hydrothermal-Sanitary Systems Distribution
- Founded
- 1929
Attack summary
Severity: high — Data has been confirmed as published by the threat actor, indicating successful exfiltration of business data from a significant Italian distributor. While the specific data categories and volume are not enumerated, publication of stolen data from a company of this scale and commercial reach constitutes a high-severity incident.The Snatch ransomware group claims to have attacked Comoli Ferrari and has published data (disclosed status: data_published), indicating confirmed exfiltration of company data. No specific ransom demand or data size was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company business data
- Customer records
- Supplier information
- Internal documents
What the group claims
Comoli Ferrari è uno dei maggiori distributori di soluzioni per l’impiantistica elettrica e idrotermosanitaria completamente italiano, da anni il benchmark di clienti e fornitori di un ampio mercato impiantistico che ricerca prodotti, soluzioni e competenza per quadri elettrici, automazione, domotica, sicurezza, illuminazione, climatizzazione, antenne, cavi,
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

