Ransomware victim disclosure
← All victimsCO.GE.S.I. (Gruppo Cogesi)
listed as gruppocogesi.org · Claimed by lockbit3 · listed 1 year ago
Status timeline
- Listed
Mar 2, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileCO.GE.S.I. is a specialized service provider based in Guidonia Montecelio (Rome), Italy, with over a decade of experience. The company focuses on technical and administrative support to public administrations, particularly in building permit regularization (condono edilizio) and digitization of municipal processes.
- Industry
- Administrative & Technical Services to Public Administration
- Address
- Via Lago dei Tartari, 73 - 00012 Guidonia Montecelio (RM), Italy
Attack summary
Severity: medium — Data has been published by LockBit3 and the victim is confirmed to handle sensitive municipal administrative records and building permit data for public administrations. However, no specific data inventory, proof files, or scale of exfiltration is detailed in the available post. The target's role managing PA processes elevates concern beyond routine business data.LockBit3 claims to have attacked CO.GE.S.I. and published data. The group post does not specify what data was exfiltrated or whether encryption occurred, only confirming the company's service focus.
Data the group says was taken
AI dossier — extracted from the leak post- Administrative records
- Building permit documentation
- Municipal process data
- Document management systems
What the group claims
CO.GE.S.I. si è specializzata nel supporto tecnico – amministrativo finalizzato alla definizione delle istanze di condono edilizio e delle istanze edilizie presentate ai sensi del D.p.r. n. 380/2001.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
