Ransomware

LockBit 5.0 Claims Responsibility for Attack on the Fund for Standardization and Quality Certification (FONDONORMA)

Screenshots of local evidence show a list of Lockbit 5.0 leak sites for fondonorma.org.It includes an upload timestamp of April 9, 2026, a deadline of April 24, 2026, and references to additional links containing alleged stolen data. Ransomware.live and DeXpose also indexed or reported a Lockbit 5.0 claim against Fondonorma in April 2026. No official confirmation or independently verified leaked data has been found, so the incident should be treated as a claim by a threat actor rather than a confirmed breach.

Overview

Missing evidence

No official confirmation or denial was found from FONDONORMA.No independently verified samples of leaked data were found.The material impact on the business, the systems affected, and the number of people affected are unknown.

Impact details

LockBit 5.0 lists FONDONORMA as a victim and threatens to leak data; no public confirmation of encryption, disruption, or data authenticity has been found.

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
Medium

Ransomware.live and DeXpose report a LockBit 5.0 leak site/ransomware claim against FONDONORMA; public sources do not confirm encryption or operational disruption.

Severity assessment

Medium
Information impact
Suspected
Affected scope
Organization-wide
Critical service
None
Public confidence
Limited
Recoverability
Extended

Public tracking of ransomware incidents and media reports support a claim by LockBit 5.0 against FONDONORMA, but neither encryption, service disruption, nor data leakage has been confirmed.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

A local screenshot shows that Lockbit 5.0 lists fondonorma.org.ve as an alleged victim.

Unknown

Ransomware.live has indexed fondonorma.org.ve as a Lockbit5 attack with an estimated attack date of April 9, 2026.

Evidence & sources

2 sources