Ransomware victim disclosure
← All victimsNordenta (a daughter company of LIFCO)
Claimed by kairos · listed 1 month ago
Status timeline
- Listed
Apr 20, 2026
- Data leaked
At a glance
- Group
- kairos
- Status
- Data leaked
- Country
- DK
- Sector
- Healthcare
- Listed on leak site
- Apr 20, 2026
About the victim
AI dossier — public-source company profileNordenta is a Danish dental supply company and a subsidiary of LIFCO, the Swedish industrial conglomerate ultimately controlled by Carl Bennet. Nordenta distributes dental products and publishes a trade newsletter ('al dente') offering deals, product news, and inspiration to dental professionals in Denmark.
- Industry
- Dental Supplies & Distribution
Attack summary
Severity: high — Data has been confirmed as published (data_published status) involving personal data of customers including email addresses and consent records in a healthcare-adjacent sector; GDPR-regulated PII exfiltration and publication elevates severity to high.The Kairos ransomware group claims to have attacked Nordenta and has published data, though the leak post excerpt does not specify whether encryption, exfiltration, or both occurred; the disclosed status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Customer email addresses
- Marketing consent/opt-in records
- Personal data subject to privacy policy
- Internal newsletter subscriber data
What the group claims
Nordenta og al dente nyhedsbrev Tilbud, produktnyheder og inspiration Ja tak, jeg vil gerne modtage tilbud, information og nyheder fra Nordenta og al dente via e-mail vedrørende varer og services inden for Nordenta og al dentes produktsortiment. Samtykket kan til enhver tid trkkes tilbage. Personoplysninger behandles fortroligt, ls mere i vores privatlivs- og cookiepolitik. "The beneficial owner of Nordenta is Carl Bennet".
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
