Ransomware victim disclosure
← All victimsCasadei
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 19, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCasadei is an Italian luxury footwear brand headquartered in San Mauro Pascoli, Forlì-Cesena, Italy, founded in 1958. The company designs and sells high-end women's shoes — including décolleté, sandals, boots, and sneakers — as well as bags and accessories, with a strong Made in Italy heritage and international retail presence. Casadei is known for iconic styles such as the Blade heel and collaborates with fashion designers.
- Industry
- Luxury Footwear & Fashion Accessories
- Employees
- 51-200
- Founded
- 1958
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by Qilin, a known ransomware/extortion group, indicating confirmed exfiltration and public release of company data. Casadei is a consumer-facing luxury brand likely holding customer PII and business-sensitive information.The Qilin ransomware group has listed Casadei as a victim with a disclosed/published status, claiming data has been exfiltrated and published. No specific data size or ransom amount was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Customer records
- Internal documents
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

