Ransomware victim disclosure
← All victimsVan Metropolitan Municipality
listed as City government office in Van · Claimed by Skira · listed 1 year ago
Status timeline
- ListedMar 6, 2025
- Data leakeddate unknown
At a glance
- Group
- Skira
- Status
- Data leaked
- Country
- Turkey
- Sector
- Public Sector
- Listed on leak site
- Mar 6, 2025
About the victim
AI dossier — public-source company profileVan Metropolitan Municipality is the administrative body responsible for local governance in Van, Turkey. It manages municipal services including urban planning, public facilities maintenance, and local administrative operations essential to the city's infrastructure and daily operations.
- Industry
- Public Administration & Local Government
- Address
- Van, Turkey
Attack summary
Severity: medium — Public sector entity with potential access to citizen data and municipal records; however, no proof files are advertised, no exfiltration is explicitly confirmed, and no operational disruption is documented. Classification reflects the sensitivity of government data and claimed disclosure status, tempered by lack of evidence.The skira group claims to have compromised the Van city government office (van.bel.tr). No specific details about encryption, exfiltration method, or data scope are provided in the available post.
Data the group says was taken
AI dossier — extracted from the leak post- Municipal administrative records
- City governance databases
- Public service records
Original description
AI-summarised, not from the leak postCity Government Office in Van, Turkey, also known as van.bel.tr, is an administrative body responsible for local governance in the city of Van. It is involved in a range of municipal tasks such as urban planning, delivering local services, maintaining public facilities, and more. The office is a crucial component of the city’s infrastructure, supporting the growth, sustainability, and daily operations of Van.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

