Ransomware victim disclosure
← All victimsPegasus SRL
listed as pegasussrl.com · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Italy
- Sector
- Business Services
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profilePegasus SRL is an authorized Unipol insurance agency (R.U.I. N. A000671187) operating in Prato, Agliana, and Campi Bisenzio, Italy. The agency offers insurance products and consulting services under the UnipolSai brand, covering mobility, home, business, and personal protection. It is a small independent agency with a local team of consultants serving individual and corporate clients.
- Industry
- Insurance Agency (Unipol/UnipolSai)
- Address
- Prato, Agliana e Campi Bisenzio, Italy (specific street address not stated on public site)
Attack summary
Severity: critical — The company is an insurance agency handling regulated PII and financial/insurance data of clients at scale. Data has been published (not merely listed), meaning sensitive customer insurance records, personal details, and financial information are confirmed exfiltrated and exposed.LockBit 5 claims to have attacked Pegasus SRL and has published data (disclosed status: data_published), indicating exfiltration of company and client data. No ransom amount was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Client insurance policy records
- Personal identification data (PII) of policyholders
- Contact information (names, emails, phone numbers)
- Insurance quotes and application forms
- Internal business documents
What the group claims
Agenzia Unipol Assicurazioni 39547 Prato - Pegasus srl Agenzia 39547 Prato R.U.I. N. A000671187- P....
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

