RANSOMWARE VICTIMCONSTRUCTION

Trevi

nova📍 Italy (IT)📅 June 9, 2026
8
same group

Attack Intelligence

Trevi was compromised in a ransomware attack attributed to nova in June 2026. The organization, operating in the Construction sector in Italy, was added to the group's data leak site as part of an extortion campaign.

nova operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

The trevi.it website is the official brand portal for the Italian consumer electronics company Trevi S.p.A., which is owned by Trevidea srl - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.

Additional Details

Other Victims — nova (8)

Quick Facts

CountryItaly (IT)
SectorConstruction
Attack DateJun 9, 2026
Intel Sourceransomware.live

Threat Group

nova
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.