Hackers threaten to leak Italian gas giant's data
A notorious Russia-linked ransomware gang has claimed to have stolen 159GB of data from one of Italy’s largest industrial gas producers and has begun the countdown to release it publicly.
The Everest Group, the Russia-linked cybercriminal gang behind the alleged ransomware attack, has listed the SIAD Group as a victim on its leak site on the dark web.
The SIAD Group is one of Italy’s leading chemical and industrial gas companies, producing and distributing gases used across sectors such as food, healthcare, automotive, metallurgy, and chemical manufacturing. Its operations also include the supply of liquefied petroleum gas (LPG) and natural gas.
Beyond gas production, the company develops gas plants, compressors, and automation systems, and provides and hospital healthcare services. Founded in Bergamo in 1927, SIAD has reported a turnover exceeding €1.1 billion in 2024.
For now, the gang has not released a data sample to back up its claims. The post on its victim site includes a timer, showing that the company has eight days to the cybercriminals before the stolen data is released.
Ransomware gangs often list their victims on dark web leak sites, attempting to blackmail organizations into paying a ransom.
It’s still too early to determine the scope or implications of the potential data breach.
“No proof has been uploaded yet. Therefore, we don't know what systems could have been affected,” Cybernews researchers said.
“Since SIAD Group is a major supplier of various industrial consumables, if the ransomware attacks halt their production and operations, it may lead to an inability to deliver the consumables used by their clients, which may lead to moderate disruptions in manufacturing, healthcare, and the energy sector, mainly in the EU,” our researchers added.
Cybernews has reached out to the company for clarification, but a response has not yet been received.
The Everest gang, likely linked to Russia, first emerged on the scene in July 2021. The most disruptive attack conducted by the gang this year has affected the aviation sector.
The gang claimed a breach of Collins Aerospace and its MUSE check-in software , which is used for check-ins and passenger management.
The attack affected multiple major airports across Europe, causing travel chaos for several days. Later, the gang threatened to release passenger data from Dublin Airport in connection with the Collins Aerospace breach.
In September this year, the gang claimed BMW as a victim. It also claimed that it breached a subsidiary of Germany's second-largest bank, DZ Bank , and threatened to release stolen data. However, the bank denied that any attack took place.
In July, the group claimed Mailchimp, the popular email marketing platform, along with a cache of “internal company documents.” However, some security insiders referred to it as “breadcrumbs.”
Believed to be connected to the BlackByte ransomware group, on May 22nd, Everest set its sights on Coca-Cola’s Middle East division, eventually leaking the data of nearly 1000 employees from the company’s multiple distribution centers.
Seemingly part of a broader attack on Coca-Cola Europacific Partners , the world’s largest Coca-Cola bottler, the ransomware group reportedly stole an alleged 23 million records.
Just days after the attack on Coca-Cola, Everest claimed the prominent international private hospital Mediclinic , which has locations in the UAE, the Abu Dhabi Department of Culture and Tourism , and the Jordan Kuwait Bank (JKB).
The gang was also behind the October 2022 attack on AT&T , allegedly offering access to the entire AT&T corporate network, as well as the Radisson Country Inn and Suites hotel chain in fall 2024.
Unlock more exclusive Cybernews content on YouTube.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
