Ransom! Sandberg

The ransomware claim involves incransom targeting Sandberg, a leading materials testing consultancy in Great Britain, by exfiltrating 100GB of highly sensitive data including confidential documents, client information, NDAs, financial records, operational data, and business agreements. The breach poses a significant threat to Sandberg’s operations and reputation, impacting the United Kingdom.

Incident Details

  • Victim: Sandberg
  • Sector: Not Found
  • Country: GB
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/696f04578f1d14b743278cb2
  • Discovered: 2026-01-20 05:55:07.442309
  • Published: 2026-01-20 01:20:00.000000

Information

  • Sandberg is an independent consultancy firm established in 1860, specializing in materials testing, inspection, and consultancy services within the construction industry.
  • The company provides a variety of services including laboratory testing, site inspections, and quality assurance for materials such as concrete, stone, and metals.
  • The ransom amount demanded was 100GB of data.
  • The data collected includes confidential documents, client data, NDAs, financial data, operational information, corporate data, business agreements, development records, financial databases, transaction histories, and client information.
  • The actor responsible for the ransomware attack is incransom.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live