Ransomware victim disclosure
← All victimsMetallco AS
listed as Metallco · Claimed by Play · listed 6 hours ago
Status timeline
- ListedSep 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- Brazil
- Sector
- Manufacturing
- Listed on leak site
- Sep 21, 2026
About the victim
AI dossier — public-source company profileMetallco is Norway's leading metal and scrap recycling conglomerate, headquartered in Oslo with operations nationwide. The company collects, sorts, and processes scrap metal into new raw materials for industrial use in Norway, Europe, and Asia. Services include vehicle dismantling (14 locations), EE-waste processing (4 locations), metal fragmentation, and secondary aluminum alloy production.
- Industry
- Metal & Scrap Recycling
- Address
- Oslo, Norway (headquarters); multiple facilities across Norway including Fredrikstad, Gjøvik, Bergen, Trondheim, and others
Attack summary
Severity: low — The leak post contains no substantive disclosure—only the country name. No proof files, screenshots, or data samples are advertised. No confirmation of exfiltration or encryption impact. Listing only.The Play ransomware group claims to have compromised Metallco. The leak post is minimal (containing only 'Norway') and provides no details about what data was exfiltrated, what systems were encrypted, or the scope of the attack.
What the group claims
Norway
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

