Ransomware victim disclosure
← All victimsSofinter S.p.a
Claimed by Payoutsking · listed 2 months ago
Status timeline
- ListedApr 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Payoutsking
- Status
- Data leaked
- Country
- Italy
- Sector
- Business Services
- Listed on leak site
- Apr 30, 2026
About the victim
AI dossier — public-source company profileSofinter S.p.A. is an Italian industrial group specializing in the design and manufacturing of large industrial boilers, steam generation systems, and waste-to-energy plants. Operating globally, the company serves oil & gas, petrochemical, power generation, and waste management sectors, with production facilities including a site in Gioia del Colle.
- Industry
- Industrial Boilers & Thermal Energy Equipment
- Address
- Via Conservatorio, 17 – 20122 Milano, Italy
Attack summary
Severity: medium — Confirmed data exfiltration with public disclosure by ransomware operator, but no specific proof files enumerated, data categories clarified, or operational impact stated. The company has acknowledged an 'information security incident' (febbraio 2026 news item), supporting the breach claim.The ransomware group payoutsking claims to have compromised Sofinter and published exfiltrated data. No specific details on data categories or encryption are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate/operational data
- Potentially sensitive business records
Original description
AI-summarised, not from the leak postSofinter S.p.A. is an Italian industrial company specializing in the design and manufacturing of heat recovery systems, boilers, and thermal energy equipment. Operating in the energy and power generation sector, it serves industries including oil and gas, petrochemical, and power plants. Headquartered in Italy, Sofinter provides engineering solutions focused on steam generation and waste heat recovery, supporting both domestic and international markets.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

