Ransomware victim disclosure
← All victimsWilhelmsen
listed as wilhelmsen.com · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Norway
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileWilhelmsen is a Norway-based global maritime industry group founded in 1861, operating one of the world's largest maritime networks spanning shipping, ship management, port services, and maritime products. The group serves customers across more than 70 countries and is one of the most significant players in the international maritime sector. Its business lines include Wilhelmsen Ship Management, Wilhelmsen Ships Service, and Wallenius Wilhelmsen logistics.
- Industry
- Global Maritime Shipping & Services
- Address
- Strandveien 20, 1366 Lysaker, Norway
- Employees
- 10000+
- Founded
- 1861
Attack summary
Severity: high — Wilhelmsen is a major global maritime group with critical logistics infrastructure; the disclosure status is 'data_published', confirming exfiltration has occurred and data has been released, representing significant business and potentially regulated data exposure at scale.The LockBit 5 group claims to have attacked Wilhelmsen and has published data ('data_published' status), indicating exfiltration of company data. The specific volume of data or nature of files stolen has not been detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Potentially employee records
- Potentially financial records
- Potentially operational/logistics data
What the group claims
Founded in Norway in 1861, Wilhelmsen is a global maritime industry group. With the world's lar...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

