Data breach
Bonava
- Records
- 525,721
- Breach date
- 26 July 2026Estimated
- Added
- 9 August 2026
What was exposed
5 types of data · 5 more reported · 1 puts you at serious risk
- Email addresses525,721
- Names498,075
- Phone numbers454,785
- Dates of birth121,623
- Passport numbers117
- Government IDsReported, not counted
- Home addressesReported, not counted
- Marital statusReported, not counted
- GenderReported, not counted
- EmploymentReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Swedish residential developer Bonava has confirmed a data breach involving customer and lead records after the data extortion group ExfilSquad claimed responsibility for stealing its data. According to our investigation team, the listing covers 525,721 rows of personal information, and Bonava's own customer notice describes unauthorized access to a limited part of its customer and complaint system. The incident is part of a wider campaign in which ExfilSquad claimed to have hit 15 organizations, with security researchers at Fortra tracing the intrusions to exposed Microsoft Dynamics 365 data, most likely through misconfigured Power Pages portals rather than a network-wide hack.
Breach Timeline
July 26, 2026: ExfilSquad listed Bonava on its leak site, claiming 13.2 GB of data including roughly 842,000 records, as tracked by ransomware.live.
July 27, 2026: Bonava was notified by Swedish police of a potential breach and began an investigation, according to the company's customer notice.
July 28, 2026: ExfilSquad released data samples to back up its claims, per Fortra's analysis.
August 7, 2026: The group published full data dumps of 13 claimed victims via torrent, including an archive attributed to Bonava, according to Fortra.
What Information Was Compromised?
Our analysis found the following data types in this breach: names for 498,075 individuals, email addresses for 525,721, phone numbers for 454,785, dates of birth for 121,623, and 117 passport records.
Bonava's own notice lists additional fields drawn from its customer and complaint system: address, home and/or work phone and email, marital status, gender, contact preference, sales status, housing preferences, warranty and complaint claim information, and in some cases Swedish personal identity numbers, dates of birth, and occupation. The company says its investigation found no evidence that other personal data or documents were affected.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Bonava itself warns of an increased risk of phishing, fraud, and identity theft. Names paired with phone numbers, email addresses, and property interests give scammers material for convincing messages that appear to come from a builder, bank, or service provider. Because some records include Swedish personal identity numbers, the exposure is more serious than a typical contact-list leak: those numbers are central to identity verification in Sweden and are difficult to change. Warranty and complaint details could also be used to make fake customer service claims feel credible.
What Is Bonava Doing in Response?
According to its notice, Bonava was alerted by Swedish police on July 27 and immediately opened an investigation with external cybersecurity experts. The company says it has strengthened security in its customer and complaint system and added technical measures to prevent similar intrusions. The incident has been reported to the Swedish Authority for Privacy Protection (IMY) and reported as a crime to Swedish police. The notice, last updated August 14, 2026, directs questions to information_se@bonava.com.
What Should You Do If You Were Affected?
Be skeptical of unexpected calls, texts, or emails referencing your home purchase, warranty case, or Bonava. Do not share personal identity numbers, passwords, or payment details in response to such contact.
Verify any message by contacting Bonava directly through its official website rather than using contact details in the message.
Watch your bank and other accounts for unusual activity. If you suspect identity fraud, report it to Swedish police.
Consider limiting how your contact details appear publicly, since scammers may combine leaked data with other sources.
If you have questions about whether your data was involved, contact Bonava at the address given in its notice.
In the news
- Fortra: ExfilSquad data extortion group analysisfortra.com (opens in a new tab)
- ransomware.live victim page for Bonavaransomware.live (opens in a new tab)
- Bonava customer notice on the data breachbonava.se (opens in a new tab)
- Perspectives.plus: analysis of the ExfilSquad Dataverse leaksperspectives.plus (opens in a new tab)
