Ransomware victim disclosure
← All victimsSunass
Claimed by Nova · listed 6 hours ago
Status timeline
- ListedJun 16, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSUNASS is Peru's public regulatory authority established by Law Decree No. 25965, responsible for regulating and overseeing water supply and sanitation services. It serves rural areas, small cities, and the general public, and conducts educational programs on water conservation and sanitation practices.
- Industry
- Water Supply & Sanitation Regulation
Attack summary
Severity: high — SUNASS is a critical national regulatory body overseeing essential water and sanitation infrastructure in Peru. Exfiltration of regulatory data, service provider details, and administrative records affecting public utilities constitutes significant operational and public health risk.Nova group claims to have exfiltrated data from SUNASS and published samples. The post indicates stolen data was accessed, though specific data categories and operational impact are not detailed.
Data the group says was taken
AI dossier — extracted from the leak post- regulatory records
- service provider information
- administrative documents
What the group claims
SUNASS is a public regulatory body established by Law Decree No. 25965, with legal personality and administrative, functional, technical, economic, and financial autonomy. The organization focuses on regulating and overseeing water supply and sanitation services in Peru. Its intended clients include service providers in rural areas and small cities, as well as the general public seeking information and assistance regarding water and sanitation services. SUNASS also engages in educational programs and campaigns to promote water conservation and proper sanitation practices - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

