Ransomware victim disclosure
← All victimsGrad Rovinj-Rovigno (City of Rovinj-Rovigno)
listed as rovinj-rovigno.hr · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileGrad Rovinj-Rovigno is the official municipal government of the City of Rovinj-Rovigno, located on the Istrian coast of Croatia. It administers public services including urban planning, finance, communal economy, social activities, and property management for the city and its residents. The municipality is a prominent Croatian tourist destination and has received multiple national awards for tourism and governance transparency.
- Industry
- Municipal Government Administration
- Address
- Trg brodogradilišta 1, 52210 Rovinj, Croatia
Attack summary
Severity: high — The victim is a municipal government with data_published status, indicating confirmed exfiltration. Municipal systems typically hold citizen PII, financial records, and GDPR-regulated data at scale, warranting a high severity rating. Elevation to critical would require confirmed volume or specific sensitive categories (e.g., health, law enforcement data).LockBit 5 claims to have attacked the City of Rovinj-Rovigno municipal government and has published data (disclosed status: data_published). The leak post alludes to the city's Istrian coastal location, suggesting data exfiltration from municipal systems containing citizen and administrative records.
Data the group says was taken
AI dossier — extracted from the leak post- Municipal administrative records
- Citizen personal data (PII)
- Financial and budget documents
- Public procurement records
- Urban planning documents
- Employee records
- GDPR-regulated personal data
What the group claims
The beautiful coast of Istria, contiguous to the Lim Canal, is where you will find the most romantic...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

