Ransomware victim disclosure
← All victimsEHG Dienstleistung GmbH
listed as ehg.bayern · Claimed by Safepay · listed 11 days ago
Status timeline
- ListedJun 22, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileEHG Dienstleistung GmbH is a Bavaria-based service company founded in 1991, specializing in facility operations and sustainable energy solutions. The company operates crematorium facilities, geothermal and photovoltaic installations, and provides energy consulting services with a strong focus on environmental sustainability and climate neutrality.
- Industry
- Infrastructure Operations & Renewable Energy Services
- Address
- Chiemgau region, Bavaria, Germany (specific address not disclosed in available excerpts)
- Founded
- 1991
Attack summary
Severity: medium — Data has been published by the ransomware group (disclosed_status confirms 'data_published'), but the available excerpts do not specify the volume, sensitivity, or nature of exposed data. The company handles operational data for crematory facilities and energy infrastructure, which could include personal and operational information, but no regulated data breach (PII at scale, financial, medical) is explicitly confirmed.The SafePay ransomware group claims to have compromised EHG Dienstleistung GmbH and published data from the attack. No specific details are provided in the available excerpts regarding what data was exfiltrated or whether encryption occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational records
- Client information
- Energy/facility management data
What the group claims
Founded in 1991, the company has evolved from a regional waste management enterprise into a specialized provider of infrastructure operations, …
Sources
Source
Indexed 11 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

