takt Data Breach

Alleged

LockBit 5 Ransomware Claim Involving takt

Published: Aug 27, 2026 LockBit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
takt
Industry
Business Services
Threat Actor
LockBit
Date of Incident
Aug 27, 2026

Executive Summary

On August 27, 2026, LockBit 5 claimed takt, a Belgian digital and software services company, as a victim, as identified by SOCRadar’s Dark Web Monitoring service. While Belgium is not a primary target for LockBit 5, the group’s recent activity, with 32 victims in the past 60 days, has primarily focused on Germany, the US, and France. The targeting of takt, alongside similar European IT and digital services firms like DeCe COMPUTERS s.r.o., TECOSIM, SIRSA, and ComTRI GmbH, suggests a systematic approach by the ransomware group towards mid-market companies within these sectors. LockBit 5’s recent campaign data indicates a broader pattern of targeting industries such as Technology and Business Services. Their primary victim countries within the last 60 days have been Germany, the United States, and France. The inclusion of takt, a Belgian firm, aligns with the group’s broader strategy of targeting European mid-market IT and digital services companies, suggesting a consistent, albeit geographically expanding, operational focus.

Technical Analysis

SOCRadar’s query against takt[.]be for stealer-log records returned no positive findings. It is crucial to understand that this result does not confirm that the organization is unaffected by a compromise. The query covered a specific, paginated sample, and credentials might exist under alternate corporate domains or personal email aliases not included in the search parameters. Therefore, the absence of records in this particular dataset should be interpreted as a lack of positive indicators, not as definitive proof of the organization’s security. LockBit 5 commonly gains initial access through credentials harvested by infostealers, which are then sold on underground marketplaces. These credentials are often used to access platforms such as Microsoft 365, VPNs, or remote-access portals, serving as a precursor to ransomware deployment. Even without a direct stealer-log hit for takt, the known operational methods of LockBit 5 necessitate a continued posture of vigilance. Appropriate security actions should include ongoing monitoring of dark web and stealer-log feeds, proactive credential hygiene checks, regular password rotations, and a thorough review of multi-factor authentication configurations. Furthermore, continuous monitoring of Microsoft 365, VPN connections, and remote-access activity is recommended, alongside vigilance for any activity associated with alternate corporate domains.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.