GLOBALMalwareRetail & ConsumerRetailRansomwareLapsus$LapsusRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh
INGKA GROUP
bd_fcc60bc1ccf59376 · schema v1 · pii pii-v1
Full breach record for INGKA GROUP →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lapsus$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: Consumer ServicesDiscovered: 2026-06-13
Source: Ransomware.live
Post text · scraped from the leak site
Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories
Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident
No regulatory filing corroborates this yet. If an SEC 8-K, state-AG notice, or victim statement lands, DisclosureLens will merge it into an incident and link it here.
Source provenance
- Source URL
- https://www.ransomware.live/id/SU5HS0EgR1JPVVBAbGFwc3VzJA==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2026
- Raw hash
- 113fc3bda89d730962ccac258d882c60f7c6d1df84c4b5799367879694527ab6
Reporting entity
- Name
- lapsus$
Victim entity
- Name
- INGKA GROUPnorm: ingka group
- Industry
- Retail & Consumerllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· lapsus$
- Threat actor
- Lapsus$ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.