On February 24, 2026, industrial manufacturer Favelle Favco appeared on the leak site of the safepay ransomware group. The company, which builds tower cranes, offshore cranes, wharf and marine cranes, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, anyone whose personal or employment records were stored in those systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch favellefavco.com
Get alerted the next time favellefavco.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about favellefavco.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted details of the Favelle Favco breach on its dark-web leak site. The data consists of internal files stolen during the ransomware incident. No specific volume of records or list of exposed data types has been publicly detailed beyond the broad description of internal documents. The posting appeared on February 24, 2026, following the group’s standard practice of publishing victim data when ransom demands are not met.
Why This Matters for You and Your Family
When a manufacturer like Favelle Favco is hit, the stolen files often contain employee records, vendor contracts, customer contacts, or operational spreadsheets that include names, addresses, dates of birth, phone numbers, or email accounts. If you or a family member ever worked there, supplied parts, or interacted with the company, your information could be sitting in those files. Once leaked, that data rarely stays contained. It moves quickly through underground markets where criminals combine it with other breaches to build complete profiles.
Credential leaks from one company frequently cascade into personal email accounts, banking logins, and even gaming platforms. Children’s usernames and passwords reused from family computers are especially vulnerable. A single exposed work email can lead to reset links for personal services, turning a corporate breach into a household problem.