
Fulgar, a major Italian textile manufacturer that supplied synthetic yarns to global fashion brands such as H&M, Adidas, Calzedonia, and Wolford, was claimed as the victim of a ransomware attack that threatened to expose sensitive corporate data. The cybercriminal group RansomHouse listed the company on its dark web leak site and posted a message warning that stolen information would be released or sold unless the company met its demands.
The threat appeared on November 12, while the attackers stated that they had held encrypted data since October 31. The message directed to Fulgar’s leadership urged the company to resolve the situation to avoid the disclosure of confidential material. RansomHouse routinely used this tactic to pressure organizations into paying ransom, often releasing stolen data when victims refused.
Fulgar posted a notice on its website confirming that it suffered a cyberattack on November 3 that targeted its IT systems across Italy. The company stated that it shut down all national systems as a precaution and reported that while personal data may have been exfiltrated, no individual cases had been identified.
The attackers released samples of what they claimed to have stolen, including bank account spreadsheets, internal communications with companies and government entities, and invoices. Such information could enable highly targeted phishing attempts against employees and partners, and any disclosure of operational or financial data could weaken Fulgar’s competitive position by revealing strategic details to rivals.
Fulgar, founded in the late 1970s, grew into a global producer of synthetic yarns used in hosiery, lingerie, athletic wear, and technical fabrics. The company operated Europe’s largest spinning mill, distributed Lycra and Elaspan across multiple regions, and maintained facilities in Italy, Turkey, and Sri Lanka.
RansomHouse, active since 2021, had previously listed 148 victims on its leak site and claimed responsibility for attacks on organizations across Europe, including a major breach at Germany’s Oettinger brewery and a 2023 incident at Hospital Clinic de Barcelona that disrupted thousands of medical appointments. A 2024 advisory by U.S. cyber authorities identified Iranian state-linked actors as working with ransomware affiliates, including RansomHouse, to support encryption operations in exchange for portions of ransom proceeds.
Fulgar had not yet issued further updates or disclosed whether it planned to engage with the attackers as investigations continued.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543