BA
Ransomware Victim Agriculture and Food Production

Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano

Ransomware attack by Spacebears · Disclosed August 12, 2026 · 🇮🇹 Italy

oliobasso.com

Date Disclosed
Aug 12, 2026
2026
Threat Group
Spacebears
160 total victims
Industry
Agriculture and Food Production

ThreatAI Analysis

Compiled from this incident record and the threat intelligence profile for Spacebears. Figures and technique mappings are quoted from the source data, not inferred.

About Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano

Basso Fedele & Figli S.r.l. is a historic Italian family company founded in 1904 in San Michele di Serino, in the Irpinia region of Campania. For over a century, the Basso family has been dedicated to the production and bottling of high-quality olive oil. Today, the company is a leading name in the Italian olive oil sector, exporting its products under the Basso® brand to more than 90 countries worldwide. Combining tradition with modern technology, Basso offers a wide range of oils, including extra virgin olive oil, seed oils, and specialty blends. The company also produces private-label oils for major retail chains, maintaining a strong commitment to quality, traceability, and authenticity.https://www.villaraiano.com/Villa Raiano is the wine estate of the Basso family, established in 1996 as a natural extension of their agricultural heritage in Irpinia, Campania. The winery focuses on producing premium organic wines from indigenous grape varieties, particularly Fiano di Avellino, Greco di Tufo, and Aglianico. With approximately 27 hectares of certified organic vineyards, Villa Raiano combines traditional winemaking with modern techniques, including gravity-flow processing and minimal batonnage to preserve freshness and minerality. In 2018, the new generation of the Basso family took over management, and in 2024, a state-of-the-art underground cellar was opened for aging. Villa Raiano is now recognized as one of the most dynamic and respected wineries in southern Italy.-Personal information of employees and clients -Financial documents -Other files https://oliobasso.com/

Source record: ransomware.live

About the Spacebears group

Space Bears is a double-extortion ransomware group that emerged in April 2024, distinguished by a professional "corporate" aesthetic on its leak site, leveraging Phobos RaaS infrastructure and targeting small-to-medium organizations in manufacturing, technology, and healthcare across the US and Europe. Spacebears has listed 147 victims since April 2024.

Incident Analysis

Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano was targeted by Spacebears ransomware, one of the most active ransomware groups in our database with 160 confirmed victims globally. The attack was disclosed on August 12, 2026, when Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano appeared on the group's dark web leak site.

Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano is based in Italy , operating in the Agriculture and Food Production sector. Italy ranks #5 globally for ransomware attacks, with 555 victims in our database.

Sector context: Organisations in this sector hold valuable data and operational systems that ransomware groups seek to exploit for financial gain through encryption and data exfiltration.

Spacebears typically employs a double extortion model: first exfiltrating sensitive data from the victim's systems, then deploying ransomware to encrypt files. Victims face two simultaneous threats — paying to restore access and paying to prevent publication of stolen data. The group's leak site publishes victim names and exfiltrated data as leverage.

Data source: This incident record is sourced from public ransomware group leak site disclosures aggregated via the ransomware.live API. Disclosure date reflects when the victim was published on the leak site, which may differ from the initial date of compromise. This platform does not publish or link to stolen data. Last data update: Sep 5, 2026 14:00 UTC.

Frequently Asked Questions

Was Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano attacked by ransomware?

Yes. Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano was listed as a victim of the Spacebears ransomware group on August 12, 2026. The organisation is based in Italy and operates in the Agriculture and Food Production sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano?

Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano was attacked by Spacebears ransomware. Spacebears is one of the most active ransomware groups, having claimed 160 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano ransomware attack occur?

The ransomware attack on Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano was disclosed on August 12, 2026. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano ransomware attack?

The specific data stolen from Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Agriculture and Food Production organisation, Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano likely held sensitive business data, client information, and operational records.

How can organisations protect against Spacebears attacks?

To defend against Spacebears and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.