Nora-Lindefrakt
bd_927b4554d52aaa95 · schema v1 · pii pii-v1
Full breach record for Nora-Lindefrakt →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Sarcoma on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
An unusually vivid remnant from the war. That's how you could characterize NLF, the service company, with more than 80 years of experience, for Bergslagen's skiers and machine owners. The origin can be found in the truck centers that were formed in the early 1940s. The authorities demanded that the country's trucking companies should be united in local trucking centers. The aim was to make better use of the vehicle fleet that remained after the military deployed most of the trucks. It was also about making the best use of the scarce allocations of fuel and raw rubber for tires. When the state regulation of the haulage business ended in 1948, in most places the business was continued in association form, because the advantages were great. A common order center could handle the administration and marketing of the riders and sell transport assignments that were distributed between the riders. Today NLF is owned by around 30 haulage companies and machine contractors who together can offer most types of transport, machine contracts and material deliveries. The business also includes a quarry and industrial recycling.Geo: Sweden - Leak size: 33 GB Archive - Contains: Files, SQL
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 6, 2024
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
sarcoma
According to ransomware.live, Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.