# SpaceBears ransomware claims Basso Olio Basso

Published: 2026-08-12 · Severity: high · Sectors: manufacturing, retail
Canonical: https://vorant.io/reports/fbca0100-c860-5a41-a84f-677d50b60970/spacebears-ransomware-claims-basso-olio-basso

> Ransomware group SpaceBears listed Italian olive oil and wine producer Basso Fedele & Figli (Olio Basso/Villa Raiano) as a victim, claiming stolen employee, client and financial data.

Ransomware.live has recorded a new victim listing attributed to a group tracked as SpaceBears, targeting Basso Fedele & Figli S.r.l., an Italian olive oil producer trading as Olio Basso, alongside its affiliated wine estate Villa Raiano. The company, founded in 1904, exports products to over 90 countries and produces private-label oils for major retailers, giving it a broad international customer and partner base that could be affected by any data exposure.

The listing claims exfiltration of personal information belonging to employees and clients, financial documents, and other unspecified files. No technical details on the intrusion vector, encryption payload, or ransom demand are provided in the source posting. DNS and infrastructure details for the victim's domain (oliobasso.com) were captured but do not indicate compromise of specific cloud/SaaS infrastructure beyond standard Aruba-hosted email and DNS services.

This appears to be a routine claimed extortion listing on a ransomware leak site rather than a confirmed, verified breach with published proof. As with most such listings, the entry serves primarily as an indicator that the victim may be under extortion pressure; further validation of the claim's authenticity and scope of data theft would require direct confirmation from the victim or analysis of leaked samples.

## Mentioned in this report

- Threat actors: Space Bears
- Malware: SpaceBears

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.ransomware.live/id/QmFzc28gRmVkZWxlICYgRmlnbGkgUy5yLmwuIChPbGlvIEJhc3NvKSAvIFZpbGxhIFJhaWFub0BzcGFjZWJlYXJz

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fbca0100-c860-5a41-a84f-677d50b60970/spacebears-ransomware-claims-basso-olio-basso.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
