RANSOMWARE VICTIMDUPLICATE CLAIM

Bonheure

bonheure.co.jp
spacebears📍 Japan (JP)📅 March 1, 2026
8
same group

Attack Intelligence

Bonheure was compromised in a ransomware attack attributed to spacebears in March 2026. The organization, operating in an undisclosed sector in Japan, was added to the group's data leak site as part of an extortion campaign.

spacebears operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Karaoke BusinessOperation of a network of karaoke establishments, providing leisure and entertainment services for individual and corporate clients.        Restaurant Business (Izakaya)Development and management of a chain of food and beverage establishments, primarily in the Japanese izakaya style, as well as other concepts within the HoReCa sector.Real Estate OperationsInvolvement in the real estate market, including property management, leasing, and the potential development of commercial real estate assets.Internet Cafe ManagementOperation of internet cafes that provide customers with internet access along with ancillary services such as relaxation areas, reading materials, and refreshments. https://bonheure.co.jp/

Additional Details

Other Victims — spacebears (8)

Quick Facts

CountryJapan (JP)
Attack DateMar 1, 2026
Domainbonheure.co.jp
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

spacebears
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.