Ransomware victim disclosure
← All victimsDepona
Claimed by Qilin · listed 23 hours ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Sweden
- Sector
- Technology
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileDepona is a Swedish specialist in digital and physical archiving solutions, offering both SaaS-based systems (Visual Archive, e-Arkiv) and physical document storage. The company operates 7 archive facilities across Sweden and maintains international operations in 5 countries, serving municipalities, public institutions, and private clients requiring compliant document retention.
- Industry
- Document Management & Digital Archiving Services
- Address
- Öckerögatan 2, 211 24 Malmö, Sweden (headquarters); additional facilities in Göteborg, Katrineholm, Södertälje, Upplands-Väsby, Falun, Vilhelmina, and operations in 5 countries
Attack summary
Severity: medium — The attack is confirmed by the victim's disclosure status and website outage notification, and the company handles sensitive regulated data (municipal records, classified documents, personnel files). However, without the group's leak post details, no proof of actual exfiltration can be verified, and the scope of compromise remains unclear.The Qilin ransomware group claims to have attacked Depona. The group's leak post details are marked as 'N/A', so the specific attack vector, data exfiltration claims, and operational impact cannot be verified from the available information. The victim's public website shows a temporary service disruption notice.
Data the group says was taken
AI dossier — extracted from the leak post- Digital archives and document repositories
- Client financial records (bokföring)
- Personnel files (personalhandlingar)
- Classified/security-marked documents (säkerklassad information)
- Municipal government records
- Journal records
What the group claims
N/A
Sources
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

