Ransomware victim disclosure
← All victimsPROMOSFERA S.r.l. promosfera.com
Claimed by blacknevas · listed 10 months ago
Status timeline
- Listed
Aug 6, 2025
- Data leaked
At a glance
- Group
- blacknevas
- Status
- Data leaked
- Country
- Italy
- Sector
- Business Services
- Listed on leak site
- Aug 6, 2025
About the victim
AI dossier — public-source company profilePromosfera S.r.l. is an Italian international prize promotions and contests agency operating for 19 years across 85+ countries. They specialize in organizing sweepstakes, giveaways, and promotional campaigns for brands, offering legal consultation, contest software, and full-service management of competitions across Europe, Asia, and America.
- Industry
- Marketing Services & Promotional Contests
- Founded
- 2005
Attack summary
Severity: high — Confirmed exfiltration of personally identifiable information (PII) at scale: hundreds of thousands of email/name combinations and tens of thousands of records with phone numbers. Includes passport data and employee/client documents. No encryption mentioned, data published and monetized. Exposure spans multiple sensitive categories affecting employees, clients, and contest participants.BlackNevas claims to have exfiltrated passports, employee and client documents, and databases of promotional participants. The group states they have obtained hundreds of thousands of email addresses with full names, and tens of thousands of records with phone numbers, along with internal company documentation.
Data the group says was taken
AI dossier — extracted from the leak post- passports
- employee documents
- client documents
- promotional participant database
- email addresses (hundreds of thousands)
- full names
- phone numbers (tens of thousands)
- internal company documentation
What the group claims
passports, employee and client documents, databases of promotional participants - hundreds of thousands of emails + full names, tens of thousands of emails + full names + phone numbersinternal company documentationhttps://gofile.io/d/5gNeSzhttps://gofile.io/d/dY7rYEWe ask all our partners, friends and clients to contact us to discuss the acquisition of this data. You know the contacts. For new members, please wait in the Contacts tab.Advertising:We are always ready to cooperate in any form, do you need specific data? We will try to provide it to you as soon as possible, we will receive and download your competitors' data, provide a list of what you are interested in. We are also ready to cooperate with law firms and data leak victims. We will provide all the information you need about the company that was negligent and provided access to data to its clients.
Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
