On March 4, 2026, the French building company CTI BAT appeared on the LockBit 5 ransomware group's leak site with internal files listed for public download after the firm refused to pay an extortion demand.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch cti-bat.fr
Get alerted the next time cti-bat.fr files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about cti-bat.fr’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that LockBit 5 operators gained access to CTI BAT's systems, exfiltrated internal documents, and later published a sample of the stolen data when the company did not meet their ransom deadline. The leak site entry includes a direct link to the stolen archive hosted on the group's onion domain. No exact victim count has been disclosed, and the precise volume of data remains unclear from available screenshots and descriptions. The exposed materials consist of internal files typical of a construction and renovation business, including project records, supplier lists, and administrative documents. Ransomware.live, which tracks such incidents, mirrored the listing shortly after it appeared.
Why This Matters for You and Your Family
When a company that has handled work on homes, offices, or public buildings is breached, the information inside its files can easily include addresses, contact details, contract values, and sometimes even family names tied to renovation projects. If those records contain your information, it can surface in unexpected places. Credential leaks from related employee accounts often follow, giving attackers the raw material they need to attempt logins on personal email, banking, or shopping sites where the same password was reused. For families this means a single business breach can quietly feed longer-term risks that touch your home address, children's names, or shared accounts.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently contain spreadsheets or PDFs that link company emails, phone numbers, physical addresses, and employee or client identities. Attackers chain these fragments together with data from earlier breaches to build detailed profiles. A phone number found in one document can be matched to a gaming username, which then links to a child's account. Once the chain exists, doxxing escalates quickly: harassment, targeted phishing, or resale of the full identity package on underground forums. Credential leaks like this one regularly cascade into account takeovers precisely because the same passwords and recovery details appear across work and personal services.