RANSOMWARE VICTIMTELECOMMUNICATION
VODAFONE
vodafone.com
lapsus$📍 Germany (DE)📅 May 28, 2026
8
same group
Attack Intelligence
VODAFONE was compromised in a ransomware attack attributed to lapsus$ in May 2026. The organization, operating in the Telecommunication sector in Germany, was added to the group's data leak site as part of an extortion campaign.
lapsus$ operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Full Infrastructure, Source Code, GitHub Tree & Internal Network Maps
Other Victims — lapsus$ (8)
Quick Facts
CountryGermany (DE)
SectorTelecommunication
Attack DateMay 28, 2026
Domainvodafone.com
Intel Sourceransomware.live
Threat Group
External Links
Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.