DATALAN Listed by vicesociety Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The DATALAN Listed by vicesociety Ransomware Group (reported May 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On May 11, 2023, the Slovak technology firm DATALAN was listed by the ransomware group vicesociety, which claimed to have carried out a ransomware attack involving the exfiltration of internal files. Public detail on the incident remains limited: the number of people affected is unknown, and no further confirmed technical specifics have been widely reported beyond the group's listing and the description of internal files taken during the attack.
For an organisation that positions itself among the top technology companies in Slovakia, with more than three decades in the market and a workforce of over 220 experts, any confirmed or claimed compromise of internal material raises practical questions about operational continuity, client trust, and the potential exposure of business and personal information. What is known so far rests largely on the leak-site claim and the reported nature of the attack.
Breaking down the breach
According to available reporting, DATALAN appeared on a vicesociety listing dated May 11, 2023. The group is associated with ransomware operations that typically combine encryption of systems with the theft of data for leverage. In this case, the named exposure is described as internal files exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the precise systems involved, the initial access method, or the duration of any intrusion. The number of individuals whose information may have been touched is listed as unknown. Beyond the fact of the listing and the characterisation of the material as internal files, further operational detail has not been disclosed in the public record summarised here.
Because the primary public signal is the threat actor's own claim on its leak site, the incident should be treated as an asserted compromise pending fuller independent confirmation. Organisations in this position sometimes negotiate, restore from backups, or engage incident responders without publishing a full technical post-mortem; the absence of richer public detail does not by itself prove or disprove the scale of impact.
Inside vicesociety
Vicesociety is a ransomware group that became active in the public eye around 2021 and has been documented targeting organisations across multiple sectors, including education, healthcare, and technology and professional services. Like many contemporary ransomware operators, the group has commonly used a double-extortion model: encrypting systems to disrupt operations while also copying data and threatening to publish or sell it if demands are not met. Listings on dedicated leak sites serve both as pressure on the victim and as a signal to other potential targets.
Public reporting on vicesociety has described relatively opportunistic targeting rather than a narrow industry focus, with attacks often relying on known vulnerabilities, weak remote-access controls, or stolen credentials. The group has been linked to a series of incidents in which internal documents, employee records, and business correspondence later appeared on leak infrastructure. None of that general pattern, however, should be read as confirmed detail about the specific contents or success of any particular claim against DATALAN; for this incident, the only actor-specific assertion on record is the listing itself and the associated claim of internal-file exfiltration.
Who is DATALAN?
DATALAN describes itself as a Slovak technology company with more than 30 years on the market and a team of more than 220 experts united by technical know-how. It presents itself among the leading technology firms in Slovakia. Organisations of this type typically design, implement, and support IT systems, infrastructure, software, and related services for business and institutional clients. That work routinely involves handling project documentation, contracts, system configurations, credentials or access-related material, employee records, and correspondence that may contain personal or commercially sensitive information belonging to staff, partners, and customers.
A breach affecting such a firm is consequential not only for the company itself but for the wider ecosystem that depends on it. Technology providers often sit at the intersection of multiple client environments; even when the immediate claim concerns "internal files," the practical risk can extend to third parties whose data or system details were stored or processed in the course of normal business. Public detail does not establish that any specific client systems were reached, only that the provider itself was listed in connection with a ransomware and exfiltration claim.
What data was at risk
The facts available name the exposed material as internal files exfiltrated in a ransomware attack. No itemised inventory—such as employee databases, customer lists, financial records, source code, or authentication secrets—has been publicly confirmed in the material provided. Exact contents therefore remain unconfirmed.
Technology and IT-services organisations of DATALAN's profile commonly hold human-resources data, internal email and messaging archives, project and contract files, network or system documentation, and sometimes credentials or configuration data used to support clients. Any of those categories could in principle appear among "internal files," but stating that they were present in this incident would be speculation. Until a fuller disclosure or independent analysis is available, the prudent position is that internal corporate material was claimed to have been taken, while the precise data types and the number of affected individuals are not established in public reporting.
What's at stake
For people whose information may have been among the files, the concrete risks are familiar: possible misuse of personal details for phishing or social engineering, exposure of employment or contact data, and, if any authentication-related material was included, elevated risk of account takeover elsewhere. Because the headcount of affected individuals is unknown and the file contents are not itemised, it is not possible to quantify how widely those risks apply. Affected staff, contractors, or clients would need organisation-specific notification to know where they stand.
For DATALAN, the stakes include operational disruption from ransomware, potential regulatory and contractual obligations around personal data, reputational damage with clients who entrust the firm with technology projects, and the cost of investigation, remediation, and any required notifications. A listing by a ransomware group also creates ongoing pressure if unpublished data remains in the actor's possession. None of these outcomes is inevitable, and public facts do not establish negligence or the final severity of impact; they simply define the range of realistic consequences when internal files are claimed to have left the organisation under duress.
If your data was in this claimed breach
If you have a relationship with DATALAN as an employee, contractor, or client and you are concerned your information may have been involved, start with basic hygiene: treat unexpected emails or calls that reference the company or the incident with caution, as criminals often exploit breach news for phishing. Change passwords on important accounts, especially if you reused any credential tied to work systems, and enable multi-factor authentication where it is available. Monitor financial and account activity for unusual behaviour and consider a credit or fraud alert if you believe sensitive identity data could have been exposed. Retain any official notice you receive from the organisation; it will be more specific than general public reporting.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it can show whether your address appears in other publicly tracked compromises and help you prioritise further protections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Bogleboo Listed by vicesociety Ransomware GroupKventa Kft Listed by vicesociety Ransomware GroupTechInsights Listed by vicesociety Ransomware GroupCloudCall Listed by vicesociety Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the DATALAN Listed by vicesociety Ransomware Group →
Publicly posted by vicesociety — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.