Panorama Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Panorama was listed by the spacebears ransomware group on August 16, 2025, after internal files were exfiltrated in a ransomware attack that affected an undisclosed number of people. Individuals should check whether their information was involved and take appropriate protective steps.
On August 16, 2025, the ransomware group known as spacebears listed the organisation Panorama on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and public detail on the precise scope and method of the incident is limited.
The listing itself constitutes an unverified claim by the group. What is confirmed in available reporting is the organisation’s name, the date the listing was noted, and the description of internal files as the material said to have been taken. For clients, staff and partners of a real-estate advisory firm operating in Israel, any such claim raises practical questions about the security of business records and personal information that may have been held.
What happened
According to the reported summary, spacebears claimed responsibility for a ransomware attack against Panorama in which internal files were exfiltrated. The incident was publicly noted on August 16, 2025. No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data removed, or whether encryption of systems also occurred—have been disclosed in the available record. The number of individuals whose information may have been involved is listed as unknown. The group’s leak-site entry is treated here as a claim rather than independently verified confirmation of the full extent of the breach.
Inside spacebears
Spacebears is a ransomware operation that has appeared in public threat reporting as a group that conducts double-extortion campaigns: encrypting victim systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Like other contemporary ransomware actors, the group typically lists organisations it claims to have compromised, often including brief descriptions of the stolen material and deadlines for payment. Public knowledge of the group’s broader activity does not extend to verified statements about the specific contents or volume of data allegedly taken from Panorama beyond the claim of “internal files.” Any assertion that the group made particular demands or released particular files in this case remains unconfirmed outside the listing itself.
Who is Panorama?
Panorama operates in the Israeli real-estate sector, assisting clients—whether located in Israel or abroad—with the acquisition of property. Public descriptions of its services emphasise professional guidance on local market conditions, legal and legislative requirements, budgeting, and personal circumstances. Agents are said to remain in ongoing contact with clients throughout the process. Organisations of this type routinely handle sensitive commercial and personal information: property records, financial details, identity documents, correspondence, and contractual materials. A breach affecting such a firm is consequential because the data it holds can be used for fraud, identity misuse or competitive intelligence, and because clients may be geographically dispersed and therefore harder to notify uniformly.
The information in question
The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. Exact contents, file counts, or categories beyond that description have not been disclosed. Real-estate advisory firms of this kind typically maintain client files that may include names, contact details, financial information, identity documents, property valuations, legal correspondence and transaction records. Because those specifics have not been confirmed for this incident, it is not possible to state with certainty which of those categories, if any, were among the material claimed by spacebears. The precise nature of the exposed information therefore remains unconfirmed.
The real-world impact
For individuals who have dealt with Panorama, the primary risks are those that follow any unauthorised exposure of internal business records: potential misuse of personal or financial details for fraud or social-engineering attacks, and the longer-term possibility that contact or identity information could appear in secondary criminal markets. For the organisation itself, the consequences include operational disruption, reputational damage, possible regulatory scrutiny under applicable data-protection rules, and the cost of investigation and remediation. Because the number of people affected is unknown and the exact data types remain limited to the description “internal files,” the scale of individual harm cannot yet be quantified. Clients and staff should treat any unexpected communications that reference their dealings with the firm with caution until more verified information becomes available.
Were you affected?
If you have been a client, employee or partner of Panorama, practical first steps include monitoring financial accounts and credit reports for unusual activity, being alert to phishing or social-engineering attempts that reference real-estate transactions, and changing passwords on any accounts that may have shared credentials or recovery information with the firm. Organisations in this sector often hold data for extended periods, so even older transactions may be relevant. Readers can also take the following concrete measures:
- Review recent bank and credit-card statements for unrecognised charges linked to property or legal services.
- Enable multi-factor authentication on email and financial accounts where it is not already active.
- Treat unsolicited requests for identity documents or payment details with heightened scepticism.
- Run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets.
Public detail on this incident remains limited; further verified disclosures from the organisation or independent investigators would be required before a fuller picture of impact can be drawn.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
EXPERTISE MOBSIGN Listed by spacebears Ransomware GroupSlimsoft Listed by spacebears Ransomware GroupRAC Consultoria Listed by spacebears Ransomware GroupAmbitek Listed by spacebears Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Panorama Listed by spacebears Ransomware Group →
Publicly posted by spacebears — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.