LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › still95.it Listed by cloak Ransomware Group

HIGH severityUnverified claimHow we verify

still95.it Listed by cloak Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 24, 2023
still95.it Listed by cloak Ransomware Group

Reported August 24, 2023.

HIGH
Severity
August 24, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The still95.it Listed by cloak Ransomware Group (reported August 24, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where ransomware groups routinely list victims on leak sites to pressure payment, the appearance of an Italian organisation on such a roster is a familiar but still consequential signal. On 24 August 2023, still95.it was reported as listed by the cloak ransomware group, with the claim that internal files had been exfiltrated. The number of people affected remains unknown, and public detail beyond the listing itself is limited.

For anyone who has dealt with still95.it, or whose information may sit in its systems, the incident matters because ransomware claims of data theft create lasting uncertainty even when full confirmation is absent. What follows sets out only what has been reported, places the claim in context, and outlines practical next steps.

Breaking down the breach

According to the available record, still95.it was listed by the cloak ransomware group on 24 August 2023. The reported summary places the organisation in Italy. The listing asserts that internal files were exfiltrated in a ransomware attack. No figure has been given for the number of people affected, and the precise timing of any intrusion, the initial access method, and the full scope of systems involved have not been disclosed in the public facts.

Ransomware incidents of this type typically involve both encryption of systems and the theft of data before encryption, with the threat of publication used as leverage. In this case, the public record consists of the group’s listing and the characterisation of the material as internal files. Independent confirmation of the exfiltration volume, the exact file set, or successful decryption has not been supplied in the facts at hand. Readers should therefore treat the episode as a claimed incident whose technical particulars remain largely unverified in open sources.

Who is cloak?

Cloak is a ransomware operation that has appeared in public reporting as a group that encrypts victim environments and threatens to publish stolen data. Like other actors in this category, it has used dedicated leak sites to name organisations and, in some cases, to release samples or larger archives when negotiations stall. Public analyses of cloak activity have described the familiar double-extortion pattern: intrusion, data staging and exfiltration, deployment of ransomware, and then pressure via the threat of disclosure.

The group’s listing of still95.it constitutes a claim that the organisation was compromised and that internal files were taken. No statement in the provided facts confirms that cloak’s assertions about this specific victim have been independently validated, nor do the facts record any particular demands, deadlines, or sample files released in connection with still95.it. Prior cloak activity against other targets is documented in the broader threat-intelligence literature; those earlier cases do not, by themselves, prove the details of the still95.it listing.

still95.it and its sector

still95.it is an organisation operating under an Italian country-code domain, consistent with the reported country attribution of Italy. Beyond that, public detail in the breach record is sparse; the facts do not describe the organisation’s exact business lines, size, or customer base. Organisations of many kinds in Italy—commercial, professional, or service-oriented—commonly hold internal documents, correspondence, operational records, and data relating to staff, partners, or clients.

A breach claim against any such entity is consequential because internal files can contain material that is sensitive even if it is not classified as highly regulated personal data. Disruption to operations, reputational harm, and the secondary risk that stolen documents later appear in criminal markets or further attacks are typical concerns when a ransomware group asserts exfiltration. Without richer public disclosure from the organisation or from independent investigators, the precise role still95.it plays in its sector and the full sensitivity of its holdings cannot be stated as established fact.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included personal data, financial records, credentials, intellectual property, or operational documents—is provided. The number of individuals whose information may be involved is explicitly unknown.

Organisations of this general type typically maintain a range of internal repositories: administrative documents, email archives, contracts, employee or contractor details, and business correspondence. Any of those categories could, in principle, be present among “internal files,” yet it would be inaccurate to assert that specific categories were taken. The exact contents remain unconfirmed. Anyone who has a relationship with still95.it should therefore assume that the possibility of exposure exists without treating any particular data element as proven to have been stolen.

What's at stake

For individuals, the real-world risk centres on the later misuse of any personal or contact information that may have been among the internal files—phishing that appears more credible because it references genuine relationships, attempts to reset accounts, or social-engineering approaches aimed at staff or customers. Because the scale and composition of the data are undisclosed, the severity for any single person cannot be quantified from the public record alone.

For the organisation, the stakes include operational interruption if systems were encrypted, the cost of investigation and recovery, potential regulatory notification duties under applicable Italian and European rules, and the longer-term possibility that stolen documents surface in ways that damage trust or enable further intrusion. None of these outcomes is guaranteed by a leak-site listing; each depends on what was actually taken and how the incident was contained. The absence of a reported affected-person count simply means the human impact has not been measured in the available facts.

Were you affected?

If you have had dealings with still95.it—as a customer, employee, partner, or supplier—treat the claim seriously but proportionately. Monitor account statements and email for unusual activity, enable multi-factor authentication where available, and be wary of unsolicited messages that reference the organisation or urge urgent action. Consider changing passwords on any accounts that shared credentials or recovery details with still95.it systems, and retain records of any suspicious contact.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or deny involvement in this specific incident, but it provides a practical way to see whether your address appears in previously compiled collections and to decide what further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companystill95.it security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See still95.it’s full breach history →

More recent breaches

euro2000-spa.it Listed by cloak Ransomware GroupDecember 1, 2023farwickgrote.de Listed by cloak Ransomware GroupDecember 1, 2023BONI-PASSAU.DE Listed by cloak Ransomware GroupAugust 24, 2023werk33.com Listed by cloak Ransomware GroupAugust 24, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the still95.it Listed by cloak Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by cloak — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram