Ransomware victim disclosure
← All victimsHosab
Claimed by Nova · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Sector
- Business Services
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileHOSAB is an organized industrial zone operator in Bursa, Turkey, providing essential utilities and infrastructure services including natural gas, electricity, water management, wastewater treatment, and zero waste management to industrial firms and businesses.
- Industry
- Utilities & Infrastructure Management
- Address
- Bursa, Turkey
Attack summary
Severity: medium — Data exfiltration claimed with offer to provide proof/samples, but no specific sensitive data categories confirmed, no proof files publicly displayed yet, and no operational disruption stated. Infrastructure utility exposure is notable but unconfirmed.Nova claims to have exfiltrated data from HOSAB and is offering to provide samples and files to the company upon contact with their support department.
Data the group says was taken
AI dossier — extracted from the leak post- operational data
- business records
What the group claims
HOSAB, an organized industrial zone in Bursa, offers a range of services including natural gas, electricity, water management, wastewater treatment, and zero waste management. The company aims to support local businesses and industries by providing essential utilities and infrastructure. HOSAB is committed to sustainability, having received certifications for its environmental management systems. Its intended clients include industrial firms and businesses operating within the organized industrial zone - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

