Ransomware victim disclosure
← All victimsIveta d.o.o.
listed as Iveta · Claimed by Thegentlemen · listed 20 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Croatia
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileIveta is a Croatian family-owned confectionery and bakery based in Split, established in 1985. They produce traditional Dalmatian specialties including Splitska torta, mandulato, zabac, and custom celebration cakes. The business operates multiple cafés in Split and Trogir, supplies hotels and restaurants across Dalmatia, and sells online and to tourists.
- Industry
- Confectionery & Bakery
- Address
- Split, Croatia
- Employees
- 10-20
- Founded
- 1985
Attack summary
Severity: low — No proof files, screenshots, or operational impact documented; no data types or volumes specified; appears to be listing announcement only with no evidence of actual exfiltration or encryption.The threat actor claims access to Iveta's systems but provides no description of encryption, exfiltration, or specific data compromised. The post appears to be an announcement listing rather than a substantive breach claim.
What the group claims
iveta.hr rocketreach.co/iveta-doo-windows-and-doors-profile_b58bc102f9eb0201 Iveta Croatian family confectionery & bakery from Split — traditions since 1985 — producing Dalmatian classics: Splitska torta (Split cake), mandulato, zabac, kroštule, bajamini and custom celebration cakes. Distribution: own cafés in Split and Trogir, B2B supply to Dalmatian hotels and restaurants, online orders; tourist-souvenir channel for the summer season. Digital: 24,000+ Facebook followers (the local 35–65 demographic lives there), active Meta ad campaigns since 2018, modest Instagram. Small family business (2nd generation), minimal public registry data (verify OIB/capital/revenue via sudreg.hr).
Sources
- Victim siteiveta.hr
Source
Indexed 20 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

