LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › dece.cz Listed by Lockbit5 Ransomware Group

HIGH severityUnverified claimHow we verify

dece.cz Listed by Lockbit5 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 27, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

dece.cz Listed by Lockbit5 Ransomware Group

Reported August 27, 2026.

HIGH
Severity
August 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

dece.cz has been listed by the Lockbit5 ransomware group, with the disclosure reported on August 27, 2026. An undisclosed number of individuals may have had personal data exposed; anyone who has interacted with the site should verify their status and review their accounts for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to use public leak sites as pressure tools, posting company names and countdown clocks whether or not an intrusion has been independently verified. In that climate, a fresh listing can spread quickly even when the underlying claim remains unconfirmed by the organisation, regulators, or established breach indexes.

On 27 August 2026, the group known as Lockbit5 listed dece.cz on its leak site. The listing presents an accusation against DeCe COMPUTERS s.r.o.; the company has not publicly confirmed the claim as of writing. Public detail is limited: the number of people who might be affected is unknown, and the listing does not disclose specific data types. What follows treats the post as a claim, explains what such listings do and do not establish, and outlines conditional steps readers can take if they later learn their information was involved.

Inside the listing

According to the Lockbit5 leak-site entry dated 27 August 2026, dece.cz appears among organisations the group says it has targeted. The publicly reported summary associated with the listing describes DeCe COMPUTERS s.r.o. as a firm that specialises in comprehensive computer and office management solutions. Beyond the name, the date of the listing, and that short organisational description, the available record does not state how any alleged access occurred, whether files were copied, what volume of material is supposedly held, or when any activity is said to have taken place.

No confirmed count of affected individuals appears in the material provided. Data categories are marked as not disclosed. In short, the listing is an unverified assertion on an extortion channel. It does not, by itself, prove that systems were compromised, that data left the organisation, or that any particular records are in third-party hands. Readers should treat subsequent reposts or screenshots with the same caution unless the company or a competent authority issues its own statement.

The group behind it: Lockbit5

Lockbit5 is a name used in connection with ransomware and data-extortion operations that follow a familiar pattern documented across many public cases: encrypt or threaten to encrypt systems, claim to have exfiltrated files, and publish victim names on a dedicated site to coerce payment. Groups operating under Lockbit branding have historically relied on affiliate models, double-extortion messaging, and timed leak threats. Those tactics are well established in open reporting on the broader Lockbit ecosystem; they do not automatically validate any single new listing.

For this entry, the group claims dece.cz is a victim. The listing does not supply independently audited evidence in the facts available here. Leak-site posts can recycle older material, inflate scope, or name organisations incorrectly. Until confirmation comes from the company or official channels, the responsible framing remains that Lockbit5 has listed dece.cz and that the claim is unproven.

About dece.cz

dece.cz is associated with DeCe COMPUTERS s.r.o., a Czech business focused on computer and office management solutions—services that typically sit at the intersection of IT support, workplace technology, and day-to-day operational tooling for client organisations. Firms in this sector often act as trusted intermediaries: they may administer endpoints, handle configuration and maintenance, support office productivity environments, and hold contractual or technical relationships with other businesses.

A claimed incident involving such a provider matters because of that intermediary role. Clients and partners may worry about shared credentials, support tickets, inventory records, or contact details even when nothing has been verified. The consequence of a listing is therefore partly reputational and partly practical: it forces stakeholders to ask conditional questions about exposure without yet knowing whether any data left the environment. That uncertainty is precisely why clear attribution—and restraint about unproven details—matters in public writing.

The information in question

The facts state that data types named as exposed are not disclosed. The Lockbit5 listing does not provide a reliable inventory, and attacker descriptions on leak sites are marketing for extortion, not audited catalogues. It is therefore not established what, if anything, was taken.

If files were taken from a company in this line of work, organisations of this kind typically hold materials such as business contact records, customer or supplier details, service contracts, internal administrative documents, device or asset information, and credentials or configuration data used to deliver IT and office services. Those categories are sector norms, not a statement of what Lockbit5 holds in this case. Exact contents remain unconfirmed, and no figure for affected people is known.

The real-world impact

For individuals and client firms, the practical risk is conditional. If business contact data or support records were involved, possible outcomes include targeted phishing that references real relationships, social-engineering attempts against staff, or misuse of email addresses and phone numbers. If technical or credential-related material were involved, the concern would extend to follow-on access attempts against related systems—again only if such material was actually obtained.

For the organisation named on the site, an unverified listing still creates operational pressure: customer inquiries, partner due-diligence requests, and the need to investigate internally while avoiding premature public conclusions. None of that proves negligence or confirms a breach; it reflects how leak-site accusations function in the current threat landscape. Scale remains unknown, method undisclosed, and independent confirmation absent as of writing.

If your data was involved

Because nothing here is confirmed, treat the following as precautions to apply if you later learn that your information was implicated, or if you have a direct business relationship with the firm and want baseline hygiene:

A leak-site name alone does not mean your data is “out.” It means a ransomware group has made a public accusation. Stay alert to verified updates, keep protective steps proportionate, and avoid treating attacker marketing as a final inventory of what happened.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companydece.cz security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See dece.cz’s full breach history →

More recent breaches

takt.be Listed by Lockbit5 Ransomware GroupAugust 27, 2026theheartcenterofmemphis.com Listed by Lockbit5 Ransomware GroupAugust 26, 2026adt.com Listed by Lockbit5 Ransomware GroupAugust 23, 2026icnavais.com Listed by Lockbit5 Ransomware GroupAugust 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the dece.cz Listed by Lockbit5 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit5 — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram