On February 19, 2026, the maritime services company Wilhelmsen confirmed that internal files had been exfiltrated by the LockBit ransomware group and posted to the attackers’ leak site.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch wilhelmsen.com
Get alerted the next time wilhelmsen.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about wilhelmsen.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Wilhelmsen, founded in Norway in 1861 and one of the world’s largest maritime industry groups, suffered a ransomware intrusion. The LockBit 5.0 operators listed the company on their dark-web leak portal, claiming to have stolen sensitive internal documents. The exact number of people whose data may have been exposed remains unknown, but the files are understood to contain employee and business partner records typical of a global enterprise of this scale. No customer-facing systems appear to have been directly impacted, yet the breach still places personal information belonging to current and former staff, contractors, and their families at risk.
February 19, 2026 marks the public disclosure date on the LockBit leak site. The data types listed include spreadsheets, PDFs, and other documents that often hold names, addresses, dates of birth, national identification numbers, contact details, and payroll or HR records.
Why This Matters for You and Your Family
When a large employer like Wilhelmsen is breached, the information that leaks can be used to target you long after the initial incident fades from the news. If you or anyone in your household has ever worked for the company, received services from it, or had a family member do so, your personal details may now sit in a criminal database. Attackers routinely sell or trade such datasets, turning one breach into dozens of follow-on scams, phishing campaigns, or identity theft attempts aimed at your family.