LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ddmontaza.hr Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

ddmontaza.hr Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 25, 2023
ddmontaza.hr Listed by lockbit3 Ransomware Group

Reported April 25, 2023.

HIGH
Severity
April 25, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The ddmontaza.hr Listed by lockbit3 Ransomware Group (reported April 25, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target industrial and infrastructure firms across Europe, treating construction and engineering companies as high-value sources of operational data and leverage. In this environment, even listings that provide limited public detail can signal real disruption for organisations whose work underpins energy, petrochemical and heavy-industry projects.

On 25 April 2023, the Croatian construction firm ddmontaza.hr was listed by the lockbit3 ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical specifics have not been disclosed. The incident matters because firms in this sector routinely handle project documentation, supplier records and workforce information that, if exposed, can create lasting operational and personal risk.

Breaking down the breach

According to available records, ddmontaza.hr appeared on a lockbit3 leak site on 25 April 2023. The reported summary describes the organisation as engaged in constructing and erecting power, petrochemical and industrial plants, bridges and steel structures. The only data-related detail provided is that internal files were allegedly exfiltrated in a ransomware attack. No confirmed figure for the volume of data, no list of specific file categories beyond the general description of internal files, and no public timeline of the intrusion or encryption events have been released. The number of individuals potentially affected is recorded as unknown. Because the listing itself constitutes a claim by the threat actor, independent verification of the full scope remains limited.

Public detail does not describe the initial access method, whether encryption was successfully deployed alongside exfiltration, or whether any ransom demand was met or refused. In the absence of those particulars, the incident is best understood as a claimed ransomware event involving the theft of internal corporate material, reported in late April 2023.

The group behind it: lockbit3

Lockbit3 is a well-documented ransomware operation that has functioned as a Ransomware-as-a-Service platform, enabling affiliates to conduct intrusions while the core group maintains leak sites and negotiation infrastructure. The group is known for double-extortion tactics: encrypting systems where possible and simultaneously exfiltrating data so that non-payment can be followed by public release or auction of the stolen material. Lockbit3 and its predecessors have claimed responsibility for numerous attacks on manufacturing, construction, logistics and professional-services organisations worldwide, often publishing victim names and sample files to increase pressure.

In this case, lockbit3’s listing of ddmontaza.hr should be treated as an unverified claim by the group. No additional statements attributed to lockbit3 about this specific victim—such as precise data volumes, ransom amounts or screenshots—are contained in the available facts. The group’s established pattern is to advertise victims on its leak site after exfiltration; whether the claimed files were ultimately published in full is not detailed in the public record for this incident.

Who is ddmontaza.hr?

ddmontaza.hr is a Croatian organisation whose business centres on the construction and erection of power, petrochemical and industrial plants, as well as bridges and steel structures. Companies in this sector typically manage complex project portfolios that involve engineering drawings, site plans, procurement records, subcontractor agreements, health-and-safety documentation and correspondence with energy and industrial clients. They also hold ordinary corporate data: employee records, payroll information, internal communications and financial files.

A breach at such a firm is consequential because the work supports critical infrastructure and heavy industry. Disruption or exposure of project-related material can affect timelines, contractual relationships and safety-critical processes. Even when the precise contents of stolen files are unconfirmed, the combination of operational and administrative data makes organisations of this type attractive targets for ransomware groups seeking both payment and secondary leverage.

What was likely exposed

The facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as employee personally identifiable information, customer lists, financial records or specific engineering documents—has been publicly named. Exact contents therefore remain unconfirmed.

Organisations engaged in industrial construction and plant erection commonly store project documentation, supplier and subcontractor details, workforce personal data, internal emails and commercial contracts. It is reasonable to expect that some mixture of these categories could have been among the internal files taken, yet that expectation is not the same as confirmed disclosure. Until more detailed inventories are released by the organisation or by independent investigators, any assertion about precise data elements would be speculative.

The real-world impact

For individuals whose information may have been present in the exfiltrated files, the primary risks are those associated with ordinary corporate data exposure: possible misuse of contact details, identity documents or employment-related information for phishing, social engineering or fraud. Because the number of people affected is unknown and the exact data types are undisclosed, the scale of personal impact cannot be quantified from public sources.

For ddmontaza.hr itself, the consequences of a ransomware incident involving data theft typically include operational interruption, costs of investigation and recovery, potential contractual or regulatory notifications, and reputational pressure arising from the public listing. Clients and partners in the power, petrochemical and infrastructure sectors may also reassess information-sharing practices. None of these outcomes depends on proving negligence; they follow from the simple fact that internal material left the organisation’s control.

Secondary effects can linger. Even if files are not immediately published, the existence of stolen data creates an ongoing possibility of later leaks or sale. Project-related documents, if sensitive, could in theory assist competitors or hostile actors, though no such use has been documented in the available facts for this case.

If your data was in this claimed breach

If you have a past or present connection to ddmontaza.hr—as an employee, contractor, supplier or client—treat the possibility of exposure seriously while recognising that Reported Details are limited. Monitor financial and email accounts for unexpected activity, and be cautious of unsolicited messages that reference the company or its projects. Consider placing fraud alerts with relevant credit or identity-protection services if you believe personal identifiers may have been involved. Change passwords on any accounts that reused credentials associated with work email, and enable multi-factor authentication where available.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or rule out inclusion in this specific incident, but it provides a practical starting point for understanding your wider exposure and deciding what further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyddmontaza.hr security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See ddmontaza.hr’s full breach history →

More recent breaches

bkf-fleuren.de Listed by lockbit3 Ransomware GroupDecember 24, 2023fager-mcgee.com Listed by lockbit3 Ransomware GroupDecember 22, 2023sterlinghomes.com.au Listed by lockbit3 Ransomware GroupDecember 22, 2023smudlers.com Listed by lockbit3 Ransomware GroupDecember 20, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the ddmontaza.hr Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram