Ransomware victim disclosure
← All victimsAplast
listed as aplast.ro · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Romania
- Sector
- Manufacturing
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileAplast is a Romanian manufacturer of PVC windows and doors with double-glazed (thermopane) units, founded in 2000. The company operates modern production lines with an annual capacity of 240,000 units and employs over 250 people. Its products are distributed across Romania through major DIY retail chains and exported to at least eight European countries including Italy, Germany, France, Greece, the Netherlands, and Austria.
- Industry
- PVC Windows & Doors Manufacturing
- Address
- Romania (headquarters; presence in București, Ploiești, Cluj-Napoca, Timișoara, Iași, Brașov, Constanța and partner networks across Central and Eastern Europe)
- Employees
- 250
- Founded
- 2000
Attack summary
Severity: high — Data has been published by the group (data_published), confirming exfiltration. The company has 250+ employees, international operations, and likely holds business, employee, and customer PII. While no specific data volume is stated, the confirmed publication of data from a mid-size manufacturer with EU market presence warrants a high severity rating.The LockBit 5 group claims to have attacked Aplast and has published data (disclosed status: data_published), indicating exfiltration of company data; no ransom amount or specific data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal files
- Business documents
- Partner/customer records
- Employee data (inferred from GDPR notices on site)
- Production/operational data
What the group claims
You are welcome in our offices across Central and Eastern Europe. With international presence since...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

