Ransomware victim disclosure
← All victimsDistrigaz Vest S.A.
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMay 29, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileDistrigaz Vest S.A. is a gas distribution company operating in Romania in the energy sector. No further details are available from public sources.
- Industry
- Gas Distribution / Energy
Attack summary
Severity: medium — Company is listed as a disclosed victim in the ransomware group's leak portal, indicating confirmed breach claim; however, no proof files, data inventory details, or specific sensitive data categories are documented in the provided excerpt. The critical infrastructure nature of gas distribution elevates concern, but lack of proof or operational impact specifics prevents 'high' classification.INC Ransom claims to have breached Distrigaz Vest S.A.'s network and exfiltrated data. The specific data compromised and operational details are not disclosed in the available leak post excerpt.
What the group claims
Distrigaz Vest S.A. is an independent gas distribution company established in 2001, the exclusive natural gas distributor in Oradea, Romania. Services include public gas distribution, network operation, and maintenance of gas infrastructure.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":712,"announcements":[{"_id":"6a18dda1d152110a6a470e18","company":{"company_name":"belimed.com","country":"US","revenue":700000000},"categories":["Proof"],"description":["We%20are%20announcing%20the%20successful%20breach%20of%20the%20secure%20network%20of%20Belimed%20AG%2C%20a%20leading%20provider%20of%20sterilization%20equipment.%20Our%20team%20has%20gained%20full%20access%20to%20the%20digital%20assets%20of%20their%20finance%20department%20and%20has%20exfiltrated%20the%20entire%20dataset.%0D","%0D","Data%20Volume%3A%201.5%20Terabytes.%0D","%0D","In%20our%20possession%20is%20the%20complete%20financial%20picture%20of%20Belimed%20AG.%20This%20isn't%20just%20tables%20or%20reports%3B%20it%20is%20the%20entire%20nervous%20system%20of%20their%20business%2C%20including%3A%0D","%0D","*%20%20%20**SAP%20(SUP)%20Databases%3A**%20Full%20dumps%20containing%20all%20operational%20and%20financial%20information.%0D","*%20%20%20**Accounting%20Records%3A**%20All%20transactions%2C%20entries%2C%20and%20financial%20operations%20spanning%20many%20years.%0D","*%20%20%20**Client%20Contracts%20and%20Payments%3A**%20Detailed%20informa…Screenshot of the leak post

Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

