CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2incident

Ixa Systems, a Vaud security integrator serving police, prisons and banks: camera locations, plans and some passwords that TheGentlemen claimed to have stolen are reported on sale on the darknet

Site plans, camera locations and some credentials of Vaud prisons and banks, and of police premises, reported for sale

Defender actions

  • If your organisation bought video-surveillance, alarm or access-control installation or maintenance from Ixa Systems, ask the firm in writing which of your sites and credentials are in the stolen data and rotate every camera, alarm, intercom and remote-maintenance credential it held.

Analysis

Le Temps reports that data stolen in a ransomware attack on a Vaud security-technology firm is now on sale on the darknet, and that the loot includes the locations of surveillance cameras, passwords and plans of security installations (Le Temps, 2026-10-06). The AWP agency names the firm as Ixa Systems of Crissier, which specialises in video surveillance, access control and burglary protection and whose customers include police authorities, banks, hospitals, schools and prisons (AWP via cash.ch, 2026-10-07). ICTjournal lists the Établissements de la plaine de l'Orbe and other judicial entities, gendarmerie premises, several banks including the Banque cantonale vaudoise and several dozen companies among the organisations concerned, and says exposure varies: for some clients the documents are limited to tenders or consultations, for others they give the location of cameras or the layout of alert buttons (ICTjournal, 2026-10-07).

Le Temps says the group TheGentlemen announced and claimed the theft on the darknet at the end of August (Le Temps, 2026-10-06). Inside IT dates the claim to 28 August and says the group made good on its threat to publish the data at the end of September (Inside IT, 2026-10-07), while ICTjournal says the documents were put on sale on 25 September and that, according to an expert's analysis seen by Le Temps, some of the data has begun to circulate (ICTjournal, 2026-10-07). The firm says it never lost use of its data, paid no ransom and that the attack gave no direct access to camera images; the canton's cybersecurity delegate says checks so far have found nothing that would compromise the security of the establishments concerned or give access to the State's IT environment, and that knowing a camera model is not enough to exploit it because the device must be reachable (ICTjournal, 2026-10-07). None of the reports states how the attackers got in.

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.