CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ixa Systems (Vaud) data theft and darknet sale (August to October 2026)

incident · incident:ixa-systems-thegentlemen-2026-08

Ixa Systems of Crissier (Vaud), an installer of video-surveillance, alarm and access-control systems whose customers include police authorities, banks, hospitals, schools and prisons, was claimed by TheGentlemen at the end of August 2026; Le Temps reported on 2026-10-06 that the stolen data, including camera locations, installation plans and in some cases credentials, is on sale on the darknet (Le Temps, 2026-10-06; ICTjournal, 2026-10-07).

Aliases: Ixa Systems data leak

Coverage
1
first 2026-10-08 → last 2026-10-08
Latest activity
2026-10-08
Site plans, camera locations and some credentials of Vaud prisons and banks, and of police premises, reported…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology · regions: switzerland
Sources cited
4
4 hosts

Action items (1)

Do-now tasks recorded on the entries about Ixa Systems (Vaud) data theft and darknet sale (August to October 2026), newest first. Check the date before acting on an older one.

  • If your organisation bought video-surveillance, alarm or access-control installation or maintenance from Ixa Systems, ask the firm in writing which of your sites and credentials are in the stolen data and rotate every camera, alarm, intercom and remote-maintenance credential it held.
    2026-10-08Site plans, camera locations and some credentials…

Defender insights

What each entry about Ixa Systems (Vaud) data theft and darknet sale (August to October 2026) tells a defender to do, newest first.

2026-10-08NOTABLESite plans, camera locations and some credentials of Vaud prisons and banks, and of police premises, reported for sale

Exposure · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-10-08Ixa Systems, a Vaud security integrator serving police, prisons and banks: camera locations, plans and some passwords that TheGentlemen claimed to have stolen are reported on sale on the darknet
    active-threatsSite plans, camera locations and some credentials of Vaud prisons and banks, and of police premises, reported for sale
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactFinancial Theft

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-10-08/ixa-systems-vaud-security-integrator-thegentlemen-sale · ATT&CK page ↗

Entries about Ixa Systems (Vaud) data theft and darknet sale (August to October 2026) (1)

2026-10-08 · view entry permalink →

NOTABLENATOB2

Ixa Systems, a Vaud security integrator serving police, prisons and banks: camera locations, plans and some passwords that TheGentlemen claimed to have stolen are reported on sale on the darknet

Le Temps reports that data stolen in a ransomware attack on a Vaud security-technology firm is now on sale on the darknet, and that the loot includes the locations of surveillance cameras, passwords and plans of security installations (Le Temps, 2026-10-06). The AWP agency names the firm as Ixa Systems of Crissier, which specialises in video surveillance, access control and burglary protection and whose customers include police authorities, banks, hospitals, schools and prisons (AWP via cash.ch, 2026-10-07). ICTjournal lists the Établissements de la plaine de l'Orbe and other judicial entities, gendarmerie premises, several banks including the Banque cantonale vaudoise and several dozen companies among the organisations concerned, and says exposure varies: for some clients the documents are limited to tenders or consultations, for others they give the location of cameras or the layout of alert buttons (ICTjournal, 2026-10-07).

Le Temps says the group TheGentlemen announced and claimed the theft on the darknet at the end of August (Le Temps, 2026-10-06). Inside IT dates the claim to 28 August and says the group made good on its threat to publish the data at the end of September (Inside IT, 2026-10-07), while ICTjournal says the documents were put on sale on 25 September and that, according to an expert's analysis seen by Le Temps, some of the data has begun to circulate (ICTjournal, 2026-10-07). The firm says it never lost use of its data, paid no ransom and that the attack gave no direct access to camera images; the canton's cybersecurity delegate says checks so far have found nothing that would compromise the security of the establishments concerned or give access to the State's IT environment, and that knowing a camera model is not enough to exploit it because the device must be reachable (ICTjournal, 2026-10-07). None of the reports states how the attackers got in.

incident08 Oct 04:52Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cash.ch1 (25%)
  • ictjournal.ch1 (25%)
  • inside-it.ch1 (25%)
  • letemps.ch1 (25%)