Ransomware victim disclosure
← All victimsGiunti Editore
listed as giunti.it · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileGiunti Editore is a historic Florentine publishing house with roots dating back to the 19th century, operating one of Italy's largest independent publishing groups. The company publishes books and magazines across a wide range of genres including fiction, children's literature, art, science, and educational titles, distributing through its own e-commerce platform and retail network. It manages multiple imprints including Bompiani, Demetra, De Vecchi, and Editoriale Scienza, among others.
- Industry
- Book & Magazine Publishing
- Address
- Via Bolognese 165, 50139 Florence, Italy
- Employees
- 201-500
- Founded
- 1841
Attack summary
Severity: high — Data has been published by the ransomware group, confirming exfiltration. As a large consumer-facing publisher with an e-commerce platform, the breach likely involves customer PII (names, addresses, payment-related data) alongside significant business data, warranting a high severity classification.LockBit 5 claims to have compromised Giunti Editore and has published data (disclosed status: data_published), suggesting exfiltration of company data; no ransom amount was stated and the specific volume of data exfiltrated was not disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company documents
- Publishing business records
- Employee data
- Customer/reader data
- Financial records
What the group claims
Giunti Editore, a historic Florentine publishing house—heir to a long publishing tradition that bega...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

