On March 20, 2024, Swedish restaurant chain Östenssons Livs AB appeared on the leak site operated by the 8base ransomware group. The company, which operates multiple locations across western Östergötland including shops in Vadstena, Skenninge, Borensberg, Linköping, and Norrköping, is claimed to have had internal files exfiltrated during a ransomware attack. The leak-site listing does not specify the number of people affected or detail exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Östenssons Livs Ab
Get alerted the next time Östenssons Livs Ab files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Östenssons Livs Ab’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the 8base Listing
The primary disclosure on the 8base leak site states that Östenssons Livs AB suffered a ransomware incident in which internal files were exfiltrated. No victim count is provided, and the listing does not quantify the volume or specific categories of data beyond claiming that sensitive internal documents were stolen. The entry was first observed on March 20, 2024, through the ransomware.live mirror of the onion-site posting at http://xb6q2aggycmlcrjtbjendcnnwpmmwbosqaugxsqb4nx6cmod3emy7sad.onion/company/7890406. As is typical with these listings, the group is using the publication to pressure the company for payment.
Why This Matters for You and Your Family
When a local business like Östenssons has internal files stolen, the information often includes customer records, supplier contracts, employee payroll data, or vendor payment details. If your name, address, phone number, email, or payment information appears in those files, the exposure creates immediate risks of identity theft, phishing, and financial fraud. Even though the exact data types remain undisclosed, any breach of internal business files routinely touches the personal information of ordinary customers and staff who interact with the company. For families in the Östergötland region who shop at these stores, the incident is not abstract; it is a direct compromise of data you may have provided during routine purchases or employment.
The Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets or databases that link names to addresses, phone numbers, email accounts, and sometimes dates of birth. Attackers and subsequent data resellers can chain this information with usernames discovered in other breaches, turning a single restaurant leak into a map of your digital life. Credential leaks of this nature often cascade into gaming account takeovers, especially for children whose parent accounts or family email addresses are tied to the same household data. Once handles are linked to real identities, doxxing escalates quickly through social media, gaming platforms, and public records. Continuous monitoring is essential because these chains surface weeks or months after the initial leak.