Ransomware victim disclosure
← All victimsCEGASA
listed as cegasa.com · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Spain
- Sector
- Manufacturing
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileCEGASA is a Spanish battery and energy storage solutions company founded in 1934, headquartered in the Basque Country, Spain. The company specialises in Lithium-Ion and Zinc-Air battery technologies for residential, commercial, industrial, marine, UPS, eMobility, and telecom sectors. It operates as a key European player in the energy transition, with over 100 global distributors and an annual production capacity of 1.2 GWh.
- Industry
- Energy Storage & Battery Manufacturing
- Address
- País Vasco (Basque Country), Spain
- Founded
- 1934
Attack summary
Severity: high — Data has been published (confirmed exfiltration) from a significant European industrial manufacturer involved in critical energy transition infrastructure; while no regulated personal data volume is explicitly confirmed, the company's scale and sector (energy storage, critical infrastructure-adjacent) elevate severity to high.The LockBit 5 group claims to have attacked CEGASA and has published data (disclosed status: data_published), asserting exfiltration of company data. No specific ransom amount or data volume has been stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal documents
- Energy solutions and R&D data
- Business/operational files
What the group claims
Cegasa is a leading European company specializing in innovative energy solutions, particularly lithi...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

