silbon.es Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The silbon.es Listed by lockbit3 Ransomware Group (reported April 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 26 April 2023, the Spanish men’s fashion brand silbon.es appeared on a leak site operated by the ransomware group known as lockbit3. The listing claims that internal files were taken in a ransomware attack. How many people may be affected remains unknown, and public detail about exactly what was copied is limited. For customers, staff, and partners who have shared personal or payment information with an international online retailer, any confirmed exposure of internal files can raise lasting practical risks around fraud, phishing, and unwanted contact.
This article sets out only what has been reported, places the claim in context, and outlines concrete steps people can take while fuller confirmation is still unavailable.
What happened
According to the available record, silbon.es was listed by the lockbit3 ransomware group on 26 April 2023. The group’s claim is that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of people affected. The precise method of intrusion, the date the attack began, whether systems were encrypted as well as copied, and whether any ransom demand was paid or refused have not been disclosed in the material provided. The listing itself is an unverified claim by the threat actor; independent confirmation of the full scope has not been supplied in the public summary.
In short, the known facts are narrow: a named organisation, a named ransomware brand, a reported date, and a description limited to “internal files exfiltrated.” Everything beyond that remains undisclosed.
Who is lockbit3?
Lockbit3 is the name associated with a prolific ransomware operation that has appeared repeatedly in public reporting since earlier LockBit variants. Groups operating under the LockBit banner have typically used a double-extortion model: they encrypt an organisation’s systems and simultaneously copy data, then threaten to publish the stolen material on a dedicated leak site if payment is not made. Affiliates often carry out the initial intrusion, while the core operation supplies the ransomware and the negotiation infrastructure. LockBit-related activity has been linked to attacks across many countries and sectors, and law-enforcement actions have at times disrupted infrastructure or unmasked individuals connected to the brand. None of that background, however, proves the specific allegations made about any single victim. In this case the only assertion tied directly to silbon.es is the group’s own leak-site listing.
Who is silbon.es?
Silbon is a men’s fashion brand focused on updating classic style, with particular attention to formalwear. It operates an online store that serves customers internationally and maintains content such as a company blog. Organisations of this type ordinarily hold customer account details, order and shipping records, payment-related information processed through their e-commerce platform, and internal business files covering suppliers, staff, and marketing. Because the brand sells directly to consumers across borders, a breach of internal systems can touch people who never set foot in a physical store yet still entrusted the company with personal data. The consequential nature of any incident therefore extends beyond the corporate network to the ordinary customers and employees whose information may reside in those systems.
The information in question
The public record states only that “internal files” were exfiltrated. No inventory of specific data types—such as names, addresses, email addresses, phone numbers, order histories, payment card data, or employee records—has been released in the facts available. It is therefore accurate to say the exact contents remain unconfirmed.
Companies in the fashion e-commerce sector commonly store customer contact and delivery information, purchase histories, loyalty or account credentials, and internal documents relating to logistics and staff. Whether any of those categories were among the files lockbit3 claims to hold has not been verified publicly. Readers should treat any detailed description of the stolen data that does not come from the organisation itself or from a competent authority as unconfirmed.
The real-world impact
For individuals, the practical risks centre on secondary misuse. If contact details or order information were among the internal files, affected people may face targeted phishing messages that appear to come from the brand, fraudulent refund or delivery scams, or attempts to reset online accounts. Even without payment-card numbers, enough personal context can make social-engineering attempts more convincing. Employees or contractors whose details sat in internal directories could face similar exposure.
For the organisation, the consequences include the operational cost of investigation and recovery, potential regulatory notification duties, and erosion of customer trust. Because the number of people affected is unknown and the precise data types are undisclosed, both the scale of individual harm and the full corporate exposure remain difficult to quantify from public information alone. Calm monitoring of financial statements and scepticism toward unexpected messages that reference recent purchases remain sensible precautions regardless of final confirmation.
Were you affected?
If you have shopped with silbon.es, created an account, or worked with the company, treat the lockbit3 claim as a reason for heightened caution rather than proof that your own data is circulating. Change passwords used on the site if you reuse them elsewhere, enable multi-factor authentication where available, and watch for unexpected emails or messages that pressure you to click links or supply credentials. Review bank and card statements for unfamiliar charges. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. Official statements from the company or from data-protection authorities, when they appear, will remain the most reliable source for confirming who was affected and what steps they recommend.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
imprex.es Listed by lockbit3 Ransomware Groupkrijnen.be Listed by lockbit3 Ransomware Grouptiautoinvestments.co.za Listed by lockbit3 Ransomware Groupeagersautomotive.com.au Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the silbon.es Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.