On December 26, 2025, the Polish engineering company Mosty Katowice appeared on the LockBit 5 ransomware leak site with internal files reportedly exfiltrated during an attack. The company, a leader in bridge and infrastructure design in Poland, had its data listed after failing to meet the group's demands, exposing potentially sensitive business and personal records to anyone who visits the dark-web portal.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch mostykatowice.pl
Get alerted the next time mostykatowice.pl files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about mostykatowice.pl’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that LockBit 5 published a post on its leak site containing samples of Mosty Katowice's internal documents. The listing states that attackers successfully exfiltrated files before encrypting systems or as part of their standard double-extortion process. No exact victim count has been released, and the precise volume or types of data remain unclear from the initial posting, though ransomware groups routinely include employee details, contracts, financial records, and correspondence in such leaks.
The incident follows the typical timeline seen in LockBit operations: initial access, data theft, encryption of victim systems where applicable, and public shaming when ransom is not paid. Available reporting describes the data as "internal files," consistent with the operational data Polish engineering firms maintain on public infrastructure projects, suppliers, and staff.
Why This Matters for You and Your Family
When a company like Mosty Katowice is breached, the information exposed often includes names, addresses, phone numbers, email accounts, and sometimes national identification numbers of employees, contractors, and their families. If your employer, your spouse's employer, or a company you have worked with appears in such leaks, your personal data can spread quickly across criminal marketplaces.