On January 18, 2026, Slovenian natural gas supplier Geoplin appeared on the leak site of the sinobi ransomware group, with the attackers claiming to have exfiltrated internal company files during a ransomware incident.
Watch Geoplin
Get alerted the next time Geoplin files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Geoplin’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from Reports
Public reporting indicates that Geoplin, a major supplier of natural gas in Slovenia since 1975, was listed on the sinobi leak portal. The company serves industrial, commercial, and residential customers across Slovenia and neighboring countries with energy optimization services and promotes natural gas as part of the shift toward lower-carbon energy. Available reporting describes the exposed material as internal files taken during a ransomware attack, though the precise volume and full list of data types have not been independently verified in open sources. No confirmed customer or employee personal data count has been published, leaving the exact scale of any personal information exposure unclear at this time.
Why This Matters for You and Your Family
When a company that supplies energy to homes and businesses suffers a breach, the ripple effects can reach ordinary households. Internal files often contain contracts, billing records, contact details, or correspondence that include names, addresses, phone numbers, and email accounts of residential customers. If your family uses natural gas for heating, cooking, or hot water, your information may be among the records now in attackers’ hands. Once such data leaves a company’s control, it can be sold, traded, or used to target you with phishing, identity theft, or scams that feel personal because the criminals already know where you live and how you pay your bills.
The Doxxing and Identity-Chain Risks
Credential leaks and internal documents rarely stay isolated. A single exposed email or phone number can be linked to your online accounts, social media handles, and even children’s gaming profiles. Attackers chain these pieces together to build a complete picture of your household, enabling doxxing campaigns that publish your address, family names, and daily routines. In incidents like this, the initial breach of a utility provider can serve as the starting point for broader harassment or financial fraud that follows your family across the internet for years.