Dutch multinational AkzoNobel has confirmed a cyberattack targeting one of its sites in the United States. The breach, which was first reported on March 2, 2026, was claimed by the Anubis ransomware group.
Incident Overview
- Confirmation: A company spokesperson confirmed to BleepingComputer that hackers breached the network of a single U.S. facility.
- Containment: AkzoNobel stated the incident was limited to that specific site and has already been contained.
- Data Impact: The Anubis ransomware group claims to have exfiltrated 170GB of data, including approximately 170,000 files.
- Exposed Information: Sample leaks allegedly contain:
- Confidential agreements with high-profile clients.
- Internal technical specification sheets and material testing documents.
- Private email correspondence and employee passport scans.
- Contact information, including phone numbers and email addresses.
Company Response
- Investigation: AkzoNobel is working with relevant authorities and taking steps to support parties potentially impacted by the leak.
- Operational Status: The company noted that the impact is limited, though they have not publicly specified if any ransom was paid or if they engaged with the threat actors.
About Anubis Ransomware
- Origins: Anubis is a Ransomware-as-a-Service (RaaS) operation that launched in late 2024.
- Capabilities: In addition to encryption and data theft, the group reportedly added a data wiper to its toolkit in June 2025 to destroy files if demands are not met.