LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Della Casa Group AG Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

Della Casa Group AG Listed by incransom Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 28, 2026
Della Casa Group AG Listed by incransom Ransomware Group

Reported July 28, 2026.

HIGH
Severity
1
Data types exposed
July 28, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Della Casa Group AG was listed by the incransom ransomware group on July 28, 2026, after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; anyone who has interacted with the company should check for official notifications and monitor their accounts.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Della Casa Group AG Listed by incransom Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Della Casa Group AG was listed by the ransomware group incransom on or around July 28, 2026, in connection with a claimed ransomware attack in which internal files were allegedly exfiltrated. Public reporting so far does not confirm how many people were affected, and independent verification of the full scope remains limited.

The listing describes a substantial volume of material and names broad categories of internal data. For clients, partners, and staff, the practical concern is whether personal, financial, or project-related information has left the organisation’s control and could be misused if the claim is accurate.

What happened

According to the publicly reported summary tied to the listing, incransom claims to have carried out a ransomware attack against Della Casa Group AG that involved exfiltration of internal files. The group’s material associated with the listing cites a data volume of 240,391,913,425 bytes, described as 86,332 files across 15,359 folders. Categories named in that material include personal and client information, accounting and finance data, details of current and future projects, and other unspecified content.

The same reported summary includes internal contact details such as telephone numbers and email addresses associated with the organisation. The number of people affected is unknown. Timing of the intrusion itself, the initial access method, whether systems were encrypted, and whether any ransom demand was paid are not disclosed in the available facts. The organisation’s listing on the group’s leak site should be treated as a claim by the threat actor unless and until independently confirmed.

Who is incransom?

Incransom is a ransomware operation known in public reporting for double-extortion style activity: operators seek to steal data before or alongside encryption, then pressure victims by threatening to publish or sell the material if demands are not met. Like other groups in this category, it has used dedicated leak sites to name alleged victims and to stage claimed data samples or full dumps as leverage.

Public documentation of the group generally describes targeting of organisations across multiple sectors rather than a single industry focus, with emphasis on internal documents that can create legal, financial, or reputational pressure. For this incident, no statements by incransom beyond the fact of the listing and the categories and volume figures reported with it should be treated as established fact about Della Casa Group AG. Claims on criminal leak sites are unverified until corroborated by the victim organisation, regulators, or independent technical analysis.

About Della Casa Group AG

Della Casa Group AG is a commercial organisation operating under Swiss contact details reflected in the reported material. Organisations of this type typically manage client relationships, internal administration, accounting, and project pipelines. That work routinely involves holding business correspondence, identity and contact data for clients and staff, financial records, and planning documents for ongoing or prospective work.

A breach affecting such an entity matters because the data it holds is not only operationally sensitive for the company but can also identify individuals and counterparties, reveal commercial terms, and expose personal or financial details that third parties could abuse. Even when the precise industry niche is not fully detailed in public breach summaries, the combination of client, finance, and project information is consequential for anyone whose records sit in those systems.

What was likely exposed

The facts name exposed material in general terms as internal files exfiltrated in a ransomware attack. The listing-associated summary further describes personal and client information, accounting and finance data, details of current and future projects, and other content, alongside the file and folder counts and total byte size noted above. Contact details including phone numbers and email addresses appear in the same reported material.

Exact contents of individual files, whether any particular customer or employee record was included, and whether full databases or only selected folders were taken are not independently confirmed in the available facts. Organisations of this kind commonly store names, addresses, contract and billing data, bank or payment-related records, internal emails, and project documentation. Those are the types of information that would be at risk if the claimed exfiltration is accurate, but specific data elements should not be treated as verified for any named individual until the organisation or official notices say so.

Why it matters

If personal or client information was taken, affected people may face phishing, social engineering, or fraud attempts that reference real names, projects, or account details to appear legitimate. Accounting and finance records can enable invoice fraud, payment diversion, or identity misuse. Project details can expose commercial negotiations, timelines, or partner relationships that competitors or criminals could exploit.

For the organisation, consequences can include regulatory notification duties, contractual obligations to clients, disruption of operations, and long-term trust damage—regardless of whether a ransom was paid. Because the count of affected individuals is unknown, the circle of people who should remain alert may be wider than those who receive a formal letter. Calm monitoring of financial accounts, caution with unexpected messages that cite company business, and reliance on official channels for updates are proportionate responses.

Were you affected?

If you are a client, employee, or partner of Della Casa Group AG, watch for notices from the company itself and treat unsolicited messages that reference this incident with care. Consider monitoring bank and credit activity, and avoid sharing passwords, codes, or payment details in response to unexpected calls or emails. You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data, which may help you decide whether to tighten passwords, enable multi-factor authentication, or place fraud alerts where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDella Casa Group AG security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Della Casa Group AG’s full breach history →

More recent breaches

foundationstofreedom.org Listed by incransom Ransomware GroupJuly 28, 2026autismuslink.ch Listed by incransom Ransomware GroupJuly 24, 2026https://eclmn.com/ Listed by incransom Ransomware GroupJuly 28, 2026greenecountyga.gov Listed by incransom Ransomware GroupJuly 28, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Della Casa Group AG Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram