Ransomware victim disclosure
← All victimsBelimed AG
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMay 29, 2026
Current state: Listed for ransom
At a glance
- Group
- Incransom
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- May 29, 2026
- Data size
- 1.5 TB
About the victim
AI dossier — public-source company profileBelimed AG is a leading provider of sterilization equipment for the medical and healthcare sectors. The company operates globally with an estimated annual revenue of approximately $700 million USD.
- Industry
- Medical Equipment & Sterilization
Attack summary
Severity: critical — Confirmed exfiltration of 1.5 TB of highly sensitive financial, operational, and employee data including banking details, SAP systems, and strategic business information. The data includes regulated employee financial information and business-critical intelligence. Public disclosure threat imminent.INC Ransom claims to have breached Belimed AG's network and exfiltrated 1.5 TB of data from the finance department, including SAP databases, accounting records, client contracts, employee data, and internal strategic documents. The group announced a one-month deadline before public release of the stolen data.
Data the group says was taken
AI dossier — extracted from the leak post- SAP databases (operational and financial)
- Accounting records and transactions
- Client contracts and payment information
- Employee salary and personal financial data
- Internal audits and strategic planning documents
- Tax documentation and banking details
The group's post references roughly 10 proof files.
What the group claims
Belimed AG, a leading provider of sterilization equipment, suffered a breach of their finance department. 1.5 TB of data was exfiltrated including SAP databases, accounting records, client contracts, employee data, internal audits, tax documentation and banking details.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":712,"announcements":[{"_id":"6a18dda1d152110a6a470e18","company":{"company_name":"belimed.com","country":"US","revenue":700000000},"categories":["Proof"],"description":["We%20are%20announcing%20the%20successful%20breach%20of%20the%20secure%20network%20of%20Belimed%20AG%2C%20a%20leading%20provider%20of%20sterilization%20equipment.%20Our%20team%20has%20gained%20full%20access%20to%20the%20digital%20assets%20of%20their%20finance%20department%20and%20has%20exfiltrated%20the%20entire%20dataset.%0D","%0D","Data%20Volume%3A%201.5%20Terabytes.%0D","%0D","In%20our%20possession%20is%20the%20complete%20financial%20picture%20of%20Belimed%20AG.%20This%20isn't%20just%20tables%20or%20reports%3B%20it%20is%20the%20entire%20nervous%20system%20of%20their%20business%2C%20including%3A%0D","%0D","*%20%20%20**SAP%20(SUP)%20Databases%3A**%20Full%20dumps%20containing%20all%20operational%20and%20financial%20information.%0D","*%20%20%20**Accounting%20Records%3A**%20All%20transactions%2C%20entries%2C%20and%20financial%20operations%20spanning%20many%20years.%0D","*%20%20%20**Client%20Contracts%20and%20Payments%3A**%20Detailed%20informa…Data the group says was taken
- SAP databases
- accounting records
- client contracts and payments
- employee data
- internal audits
- strategic planning documents
- tax documentation
- banking details
Screenshot of the leak post

Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

