Ransomware victim disclosure
← All victimsHIT d.d.
listed as HIT dd · Claimed by Akira · listed 3 hours ago
Status timeline
- ListedSep 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Listed on leak site
- Sep 23, 2026
About the victim
AI dossier — public-source company profileHIT d.d. is an entertainment and gaming provider based in Nova Gorica, Slovenia, with over 40 years of operating experience. The company operates multiple resorts and entertainment venues including hotels, casinos, wellness centers, and dining facilities across Slovenia and Bosnia and Herzegovina.
- Industry
- Entertainment & Gaming (Hotels, Casinos, Wellness)
- Address
- Nova Gorica, Slovenia
Attack summary
Severity: critical — Large-scale exfiltration (367 GB) of regulated personal data at scale (employee passports, licenses, PII) combined with financial records and client data; casinos are regulated entities handling sensitive information.Akira claims to have exfiltrated 367 GB of corporate data including detailed employee personal information (passports, licenses, names, addresses, phones, email), financial records, confidential agreements, client data, casino files, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (passports, licenses, names, addresses, phones, email)
- Financial records
- Confidential agreements
- Client data
- Casino operational files
- NDAs
What the group claims
HIT d.d. is a prominent entertainment and gaming provider based in Nova Gorica, Slovenia, offer ing a diverse range of services including hotels, casinos, wellness centers, and dining options . With over 40 years of experience, the company operates multiple resorts and entertainment ven ues across Slovenia and Bosnia and Herzegovina, catering to both local and international client s. We will upload 367gb of corporate data soon. Detailed employee personal information (passports, licenses, names, addresses, phones, email and so on), financials, confidential agreements, cli ent data, interesting casino files, NDAs and so on.
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

