CSIDB logo
Incident

Cattani

Incident posture

Attack window
Jun 2026
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-09-08 19:37

Linked entities

Victim
Cattani
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Pending
Resolved
Pending

Summary

Cattani, a dental equipment manufacturer known for exporting its products worldwide, was compromised by the ransomware group Spacebears, with the breach identified shortly before the publication of the threat intelligence report. The attack highlights the continued targeting of industrial suppliers by ransomware operators seeking to disrupt critical supply chains and exfiltrate proprietary data. The report is sponsored by Hudson Rock and offers free cybercrime intelligence tools to track infostealer infections linked to ransomware.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Cattani S.p.A., established in 1967 and described as a leader in the dental field exporting its range of products, was identified as a victim of the Spacebears ransomware group on 2026-06-10, as recorded in the recent victims list on ransomware.live. The discovery timestamp indicates the entry was added approximately three hours before the article’s publication time. The article is sourced from ransomware.live, a platform that tracks ransomware incidents and provides brief victim summaries. The entry for Cattani includes the ransomware group name Spacebears but supplies no further technical details such as attack vectors, compromised systems, or malware characteristics. No additional context regarding the timeline of the intrusion or the specific ransom demand is provided in the source material.

The source material does not specify any data exfiltration, encryption extent, operational disruption, or financial loss associated with the Cattani incident. Likewise, no information is given regarding containment measures, mitigation steps, or communication from Cattani or Spacebears. Therefore, the narrative is limited to the observed discovery and attribution as presented in the ransomware.live listing. The entry concludes with the available facts as of the article date. The lack of additional detail reflects the reporting limitations of the source at the time of publication.

Sources

Sources available to members: 1 source.

CSIDB