Ransomware victim disclosure
← All victimsIBENA Textilwerke
Claimed by nova · listed 2 days ago
Status timeline
- Listed
Jun 2, 2026
- Data leaked
At a glance
- Group
- nova
- Status
- Data leaked
- Country
- DE
- Sector
- Manufacturing
- Listed on leak site
- Jun 2, 2026
About the victim
AI dossier — public-source company profileIBENA Textilwerke is a family-owned textile manufacturer based in Bocholt, Germany, established in 1826. The company specializes in high-quality home textiles including blankets and bed linen, as well as technical textiles for industrial applications such as fireproof fabrics and automotive interior materials.
- Industry
- Home Textiles & Technical Fabrics Manufacturing
- Address
- Bocholt, Germany
- Founded
- 1826
Attack summary
Severity: high — Confirmed data exfiltration from a established manufacturing company with international business relationships (automotive brands). Threat actor demonstrating proof of access and offering decryption services indicates both encryption and data theft.Nova claims to have exfiltrated data from IBENA and is offering decryption samples and stolen data files. The group indicates operational capability to decrypt files and possesses stolen business data.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Product specifications
- Customer information
- Technical documentation
The group's post references roughly 2 proof files.
What the group claims
IBENA HEIMTEX is a family-owned textile manufacturer based in Bocholt, Germany, established in 1826. The company specializes in high-quality home textiles, including cuddly blankets, bed linen, and technical textiles for various industries. Their products cater to both consumers and businesses, with offerings such as fireproof fabrics, digital printing textiles, and car interior fabrics for renowned automotive brands. IBENA is committed to sustainability and quality, ensuring their textiles meet numerous quality standards - Nova Provide tree and samples from stolen data, free 2 files decrypt to the company when its get in touch with support department.
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
