Ransom! BASE SPA (MAY-2026)

Ransom! BASE SPA (MAY-2026)
Threat actor spacebears allegedly targeted BASE S.p.A. in Italy, claiming theft and encryption of confidential and personal employee/client information and financial documents among other files. The victim, an internationally operating freight forwarding and customs brokerage company with operations headquartered in Livorno, is reported to have been impacted in #Italy.

Incident Details

  • Victim: BASE SPA
  • Sector: Business Services
  • Country: IT
  • Actor: spacebears
  • Source: http://5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion/companies/41/base-spa
  • Discovered: 2026-05-26T05:26:35.936517+00:00
  • Published: 2026-05-25T00:00:00+00:00

Information

  • Internationally operating company active in goods inspection, commodities loading and unloading, logistic services, certifications, customs brokerage, and full assistance in international trading.
  • Founded in 1983, it grew from an international freight forwarder, custom house broker, and inspection company into a well-known provider of port services.
  • Has achieved commercial success through continuous growth, expanding its business volume and building a high-quality international network.
  • Specializes in containers and project cargo handling, waste recycling promotion, bulk dry and liquid cargo traffic, control, and survey.
  • Operative administrative centre is in Livorno, where staff, Italian branches, and global partners are coordinated and monitored.
  • Has invested continuously in staff training, innovation, and expansion of national and international structures to improve service quality.
  • Provides tailored solutions to clients to address issues related to commodity handling and ensure safe, secure trade.
  • Compromised data reportedly includes confidential information, personal information of employees and clients, financial documents, and other files.

Disclaimer: This post is based on public claims made by the ransomware group "spacebears". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live