LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Panorama Listed by spacebears Ransomware Group

HIGH severityUnverified claimHow we verify

Panorama Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 16, 2025
Panorama Listed by spacebears Ransomware Group

Reported August 16, 2025.

HIGH
Severity
August 16, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Panorama was listed by the spacebears ransomware group on August 16, 2025, after internal files were exfiltrated in a ransomware attack that affected an undisclosed number of people. Individuals should check whether their information was involved and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 16, 2025, the ransomware group known as spacebears listed the organisation Panorama on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and public detail on the precise scope and method of the incident is limited.

The listing itself constitutes an unverified claim by the group. What is confirmed in available reporting is the organisation’s name, the date the listing was noted, and the description of internal files as the material said to have been taken. For clients, staff and partners of a real-estate advisory firm operating in Israel, any such claim raises practical questions about the security of business records and personal information that may have been held.

What happened

According to the reported summary, spacebears claimed responsibility for a ransomware attack against Panorama in which internal files were exfiltrated. The incident was publicly noted on August 16, 2025. No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data removed, or whether encryption of systems also occurred—have been disclosed in the available record. The number of individuals whose information may have been involved is listed as unknown. The group’s leak-site entry is treated here as a claim rather than independently verified confirmation of the full extent of the breach.

Inside spacebears

Spacebears is a ransomware operation that has appeared in public threat reporting as a group that conducts double-extortion campaigns: encrypting victim systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Like other contemporary ransomware actors, the group typically lists organisations it claims to have compromised, often including brief descriptions of the stolen material and deadlines for payment. Public knowledge of the group’s broader activity does not extend to verified statements about the specific contents or volume of data allegedly taken from Panorama beyond the claim of “internal files.” Any assertion that the group made particular demands or released particular files in this case remains unconfirmed outside the listing itself.

Who is Panorama?

Panorama operates in the Israeli real-estate sector, assisting clients—whether located in Israel or abroad—with the acquisition of property. Public descriptions of its services emphasise professional guidance on local market conditions, legal and legislative requirements, budgeting, and personal circumstances. Agents are said to remain in ongoing contact with clients throughout the process. Organisations of this type routinely handle sensitive commercial and personal information: property records, financial details, identity documents, correspondence, and contractual materials. A breach affecting such a firm is consequential because the data it holds can be used for fraud, identity misuse or competitive intelligence, and because clients may be geographically dispersed and therefore harder to notify uniformly.

The information in question

The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. Exact contents, file counts, or categories beyond that description have not been disclosed. Real-estate advisory firms of this kind typically maintain client files that may include names, contact details, financial information, identity documents, property valuations, legal correspondence and transaction records. Because those specifics have not been confirmed for this incident, it is not possible to state with certainty which of those categories, if any, were among the material claimed by spacebears. The precise nature of the exposed information therefore remains unconfirmed.

The real-world impact

For individuals who have dealt with Panorama, the primary risks are those that follow any unauthorised exposure of internal business records: potential misuse of personal or financial details for fraud or social-engineering attacks, and the longer-term possibility that contact or identity information could appear in secondary criminal markets. For the organisation itself, the consequences include operational disruption, reputational damage, possible regulatory scrutiny under applicable data-protection rules, and the cost of investigation and remediation. Because the number of people affected is unknown and the exact data types remain limited to the description “internal files,” the scale of individual harm cannot yet be quantified. Clients and staff should treat any unexpected communications that reference their dealings with the firm with caution until more verified information becomes available.

Were you affected?

If you have been a client, employee or partner of Panorama, practical first steps include monitoring financial accounts and credit reports for unusual activity, being alert to phishing or social-engineering attempts that reference real-estate transactions, and changing passwords on any accounts that may have shared credentials or recovery information with the firm. Organisations in this sector often hold data for extended periods, so even older transactions may be relevant. Readers can also take the following concrete measures:

Public detail on this incident remains limited; further verified disclosures from the organisation or independent investigators would be required before a fuller picture of impact can be drawn.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPanorama security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Panorama’s full breach history →

More recent breaches

EXPERTISE MOBSIGN Listed by spacebears Ransomware GroupDecember 5, 2025Slimsoft Listed by spacebears Ransomware GroupDecember 4, 2025RAC Consultoria Listed by spacebears Ransomware GroupSeptember 13, 2025Ambitek Listed by spacebears Ransomware GroupAugust 19, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Panorama Listed by spacebears Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by spacebears — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram