Ransomware

LockBit 5.0 Claims Responsibility for an Attack on Comercializadora Construtodo

In December 2025, the LockBit 5.0 ransomware group claimed responsibility for an attack on Comercializadora Construtodo, a Venezuelan building materials company. The threat actor listed the company on its data leak site with a deadline of January 15, 2026, although it is unclear whether any data was actually exfiltrated or leaked.

Overview

Missing evidence

It is unclear whether any data was actually leaked or whether any material loss occurred as a result of the incident.No URL for the main leak site or official statement from the victim was found.

Impact details

LockBit 5 reportedly listed the victim on a data leak website. No confirmation of encryption, service disruption, or validated data leaks has been found.

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
Medium

Public sources report a claim by LockBit 5 (ransomware/leak site) against Comercializadora Construtodo; the encryption, service disruption, and authenticity of the data have not been independently confirmed.

Severity assessment

Medium
Information impact
Suspected
Affected scope
Organization-wide
Critical service
None
Public confidence
Limited
Recoverability
Extended

Public sources support the claim that a LockBit 5 leak site exists, but neither the encryption nor the service disruption has been confirmed, nor has the leaked data been validated.

Data exfiltration· Claimed

Timeline

Claim

Lockbit 5.0 listed Comercializadora Construtodo as an alleged victim.

Evidence & sources

3 sources