Ransomware victim disclosure
← All victimsTopackt IT Solutions GmbH
listed as topackt.com · Claimed by Lockbit3 · listed 1 year ago
Status timeline
- ListedFeb 2, 2025
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Feb 2, 2025
About the victim
AI dossier — public-source company profileTopackt IT Solutions GmbH is a German IT service provider founded in 2003, based in Speyer. They specialize in IT infrastructure, security, and cloud solutions for businesses, and have developed DNSX, a centralized network management system deployed in over 60 schools across Rhineland-Palatinate and Baden-Württemberg.
- Industry
- IT Services & Managed Security
- Address
- Altspeyerer Weide 2, 67346 Speyer, Germany
- Founded
- 2003
Attack summary
Severity: critical — Confirmed exfiltration of educational institution data affecting 70+ schools; exposure of student records and school administration systems constitutes regulated PII at scale affecting minors in the education sector.LockBit3 claims to have attacked Topackt and compromised the DNSX school management network, affecting over 70 connected schools. The group claims exfiltration of school data alongside encryption of systems.
Data the group says was taken
AI dossier — extracted from the leak post- school administration data
- student/user records
- network configuration data
- system credentials
What the group claims
Topackt IT Solutions GmbH is an IT service provider in Germany. One of its products is DNSX 'Dynamic Network for Schools X', which offers central managment of machines and users across institutions. DNSX and over 70 connected schools was attacked a...
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

