Quick Summary
AllegedExecutive Summary
SIRSA, a technology company based in Italy, has been listed as a victim on the LockBit5 ransomware group’s dark web portal, with the listing published on August 3, 2026. This information was identified through SOCRadar’s Dark Web Monitoring service. The organization operates within the technology sector in Italy and was part of a batch of European organizations added to the group’s portal. In the 60 days preceding this listing, LockBit5 claimed 76 other victims. The group’s primary targets have been the Manufacturing, Business Services, and Hospitality and Tourism sectors. Geographically, LockBit5 has predominantly targeted victims in Brazil, the United States, and Germany, with Italy appearing less frequently among their top victim countries. Recent LockBit5 victims that share similarities with SIRSA, such as being technology companies or other European organizations, include ComTRI GmbH, Spark Intertrade Co. Ltd., Ravagnan Group, and Media Service Maastricht. While technology is not among LockBit5’s top three targeted sectors during this period, SIRSA’s inclusion represents a less typical selection compared to the manufacturing and services victims that make up the majority of the group’s recent activity.
Technical Analysis
SOCRadar’s analysis of its stealer-log telemetry did not return any records for the domain sirsa.it. However, a null result does not definitively confirm that the organization is unaffected. The query covers a paginated sample of data and would not detect exposures linked to alternate corporate domains, subdomains hosted by third-party services, or credentials belonging to employees that were captured under personal email aliases. For a technology firm, these potential gaps mean that a null result should prompt ongoing monitoring rather than being interpreted as complete exoneration. The absence of evidence in this specific query does not rule out the possibility of a compromise. Infostealer-harvested credentials are a well-established initial access vector for ransomware groups like LockBit5. Threat actors or initial access brokers often obtain fresh credential logs from underground marketplaces, validate them for corporate use, and then leverage them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. It is possible that credentials associated with SIRSA may exist in data feeds not included in this query, or that compromised credentials were used and rotated before they could be indexed. Furthermore, exposure might occur under personal email aliases not directly tied to the corporate domain. Continuous monitoring of dark web sources and proactive credential hygiene checks remain crucial recommended actions for organizations.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.