On December 17, 2024, Dutch recycling firm Bnext.nl appeared on the leak site of the Black Basta ransomware group. The listing states that attackers exfiltrated roughly 500 GB of internal files during a ransomware incident and are now threatening to publish them unless the company meets their demands. Anyone whose personal or financial records passed through Bnext’s systems — employees, contractors, business partners, or clients in the Dutch construction and demolition sector — may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch bnext.nl
Get alerted the next time bnext.nl files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about bnext.nl’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Black Basta leak page explicitly names Bnext.nl and lists the compromised material as internal files totaling approximately 500 GB. Categories include financial data and accounting records, contracts and confidential data, personal employee data, project documentation, and additional unspecified files. The disclosure does not quantify the exact number of individuals affected, nor does it specify which exact records were taken beyond these broad categories. The listing remains active on the group’s onion site, indicating the extortion window has not yet closed.
Why This Matters for You and Your Family
When a company that handles payroll, contracts, or project billing for construction and demolition work is breached, your personal information can end up in criminal hands. Employee personal data often contains full names, addresses, dates of birth, national identification numbers, salary details, and bank account information. If you or a family member ever worked with Bnext.nl or one of its partners, those details could be used for identity theft, fraudulent loan applications, or targeted phishing. Even if you are not an employee, your name and contact information may appear in contracts, invoices, or project files shared with the company.
The scale — half a terabyte of internal records — suggests the exposure is broad. Construction-sector firms routinely collect sensitive data from subcontractors, suppliers, and private clients. Once that information leaves secure systems, it circulates in underground markets for months or years.