Ransomware victim disclosure
← All victimsBelimed AG
Claimed by INC Ransom · listed 3 days ago
Status timeline
- Listed
May 29, 2026
Current state: Listed for ransom
At a glance
- Group
- INC Ransom
- Status
- Listed for ransom
- Country
- US
- Listed on leak site
- May 29, 2026
- Data size
- 1.5 TB
What the group claims
Belimed AG, a leading provider of sterilization equipment, suffered a breach of their finance department. 1.5 TB of data was exfiltrated including SAP databases, accounting records, client contracts, employee data, internal audits, tax documentation and banking details.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":712,"announcements":[{"_id":"6a18dda1d152110a6a470e18","company":{"company_name":"belimed.com","country":"US","revenue":700000000},"categories":["Proof"],"description":["We%20are%20announcing%20the%20successful%20breach%20of%20the%20secure%20network%20of%20Belimed%20AG%2C%20a%20leading%20provider%20of%20sterilization%20equipment.%20Our%20team%20has%20gained%20full%20access%20to%20the%20digital%20assets%20of%20their%20finance%20department%20and%20has%20exfiltrated%20the%20entire%20dataset.%0D","%0D","Data%20Volume%3A%201.5%20Terabytes.%0D","%0D","In%20our%20possession%20is%20the%20complete%20financial%20picture%20of%20Belimed%20AG.%20This%20isn't%20just%20tables%20or%20reports%3B%20it%20is%20the%20entire%20nervous%20system%20of%20their%20business%2C%20including%3A%0D","%0D","*%20%20%20**SAP%20(SUP)%20Databases%3A**%20Full%20dumps%20containing%20all%20operational%20and%20financial%20information.%0D","*%20%20%20**Accounting%20Records%3A**%20All%20transactions%2C%20entries%2C%20and%20financial%20operations%20spanning%20many%20years.%0D","*%20%20%20**Client%20Contracts%20and%20Payments%3A**%20Detailed%20informa…Data the group says was taken
- SAP databases
- accounting records
- client contracts and payments
- employee data
- internal audits
- strategic planning documents
- tax documentation
- banking details
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
