LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › www.labiennale.org Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

www.labiennale.org Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 7, 2025
www.labiennale.org Listed by incransom Ransomware Group

Reported July 7, 2025.

HIGH
Severity
July 7, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The website www.labiennale.org has been listed by the incransom ransomware group, with internal files reported exfiltrated in an attack that came to light on 7 July 2025; the date of the intrusion itself has not been established. An undisclosed number of individuals may have been affected, so visitors are advised to review any correspondence or accounts they hold with the organisation and to monitor for signs of misuse.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose contact details, contracts or financial records may sit inside the Venice Biennale’s systems now face the ordinary but real possibility that those records have left the organisation’s control. When a ransomware group lists an institution, the practical stakes are straightforward: personal or commercial information could be published, sold or used for further fraud, and the people named in those files have little way of knowing until the data appears elsewhere.

On 7 July 2025 the ransomware group known as incransom publicly listed www.labiennale.org, the online presence of the Venice Biennale, claiming it had exfiltrated internal files. The number of people affected remains unknown and the precise contents of the files have not been independently confirmed.

Breaking down the breach

Public reporting on the incident is limited to the group’s own leak-site listing. According to that listing, internal files belonging to www.labiennale.org were taken during a ransomware attack. No confirmed date of intrusion, no confirmed volume of data, and no confirmed method of initial access have been released by the organisation or by independent investigators. The only concrete claim available is that the files were exfiltrated and that the group intends to publish material it characterises as financial.

Because the listing is an unverified claim by the threat actor, it is not yet established whether the files remain under the group’s control, whether any ransom was paid, or whether the data has already been released more widely. The scale of impact—how many individuals or partner organisations appear in the material—has not been disclosed.

Inside incransom

Incransom is a ransomware operation that follows the now-common double-extortion model: encrypting systems while also copying data and threatening to publish it if payment is not made. Groups of this type typically maintain a public leak site where they name victims and, after a countdown, post samples or full archives. Their public communications often emphasise financial or reputational pressure, highlighting payroll figures, sponsor contracts or internal budgets to increase leverage.

Like other ransomware crews active in recent years, incransom has previously listed organisations across multiple sectors. The group’s statements about any single victim should be treated as claims rather than Reported Facts until the data is independently examined or the victim organisation confirms the intrusion. In this case the only public assertion is the listing of www.labiennale.org and the truncated statement that the group now “knows how much the Venice Biennale earns” and how much sponsors and partners transfer to it.

Who is www.labiennale.org?

www.labiennale.org is the digital face of the Venice Biennale, a cultural institution founded in 1895 and widely regarded as one of the world’s leading platforms for contemporary art, architecture, cinema, dance, theatre and music. It organises major international exhibitions, research programmes and educational activities across those departments. Its current president is named in public materials as Pietrangelo Buttafuoco.

An organisation of this kind necessarily holds a range of internal records: contracts with artists and sponsors, financial ledgers, staff and volunteer details, visitor or press contact lists, and correspondence with public and private partners. A breach of such an institution is consequential because the data often links high-profile cultural figures, public funders and commercial sponsors, creating both privacy and reputational exposure that extends beyond the organisation itself.

The information in question

The only data type named in the available reporting is “internal files exfiltrated in a ransomware attack.” The group’s own text asserts that the material reveals earnings and sponsor or partner transfers, but that assertion has not been independently verified and the full contents remain undisclosed. No inventory of file names, no count of records, and no confirmation of personal identifiers have been published by any party other than the threat actor.

Organisations of this scale typically maintain financial statements, partnership agreements, payroll or contractor records, and contact databases. Whether any of those categories are present in the claimed exfiltration is unconfirmed. Until samples or a fuller disclosure appear, the exact nature of the exposed information cannot be stated as fact.

Why it matters

For individuals whose names appear in the files—staff, artists, sponsors, suppliers or correspondents—the immediate risks are identity misuse, targeted phishing and unwanted public exposure of private financial or contractual details. For the institution, the risks include disruption of ongoing exhibitions, loss of partner confidence, and the administrative burden of investigating and notifying affected parties once the scope becomes clearer.

Because the number of people affected is unknown and the data types are only broadly described, the practical impact cannot yet be quantified. The listing alone, however, places the organisation and anyone connected to its internal records in a position where monitoring for secondary misuse is warranted.

What to do if you're exposed

If you have had any professional or financial relationship with the Venice Biennale, treat the possibility of exposure as real until more information emerges. Practical first steps include:

Public detail on this incident remains limited. Further clarity will depend on official statements from the Venice Biennale or independent analysis of any material the group ultimately releases.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companywww.labiennale.org security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See www.labiennale.org’s full breach history →

More recent breaches

WSI Listed by incransom Ransomware GroupDecember 24, 2025shawhillprimaryschool.org.uk Listed by incransom Ransomware GroupDecember 16, 2025stignatiusijamsville.org Listed by incransom Ransomware GroupDecember 16, 2025bennett.edu Listed by incransom Ransomware GroupDecember 5, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the www.labiennale.org Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram