Ransomware victim disclosure
← All victimsGrimaldi Alliance
listed as grimaldialliance.com · Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedDec 18, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- Italy
- Sector
- Transportation/Logistics
- Listed on leak site
- Dec 18, 2024
About the victim
AI dossier — public-source company profileGrimaldi Alliance is an international law firm headquartered in Milan, Italy, operating across over 70 jurisdictions with significant presence in Europe and the Americas. The firm provides comprehensive legal services to national and international clients.
- Industry
- Legal Services
- Address
- Corso Europa, 12, 20122 Milan, Italy
Attack summary
Severity: critical — Confirmed exfiltration of 1.5TB+ including regulated PII (employee and client personal data), financial/payroll records, and confidential legal documents at scale from a multi-jurisdictional law firm poses significant regulatory and privacy risks.BlackBasta claims to have exfiltrated approximately 1.5TB of data from Grimaldi Alliance, including corporate, financial, HR, employee personal data, client data, and confidential legal documents including NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data
- Financial records
- Accounting data
- Payroll records
- HR documents
- Employee personal data
- Client personal data
- Confidential legal documents
- NDAs
What the group claims
Grimaldi Alliance is an international law firm based in Italy, known for providing comprehensive legal services to both national and international clients. Established as a significant player in the legal market, Grimaldi Alliance operates in over 70 jurisdictions worldwide, with a strong presence in Europe and the Americas.SITE: www.grimaldialliance.com Address : Corso Europa, 12 20122 Milan ItalyTEL#: +39 02 3030 9330ALL DATA SIZE: ≈1.5tb+ 1. Corp data, Financial data, Accounting, Payroll 2. HR, Personal employees data and documents 3. Personal clients data and documents 4. Confidential documents, NDA’s & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

