Ransomware victim disclosure
← All victimsAbwasserverband Grazerfeld
listed as awvgrazerfeld.at · Claimed by Lockbit5 · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileAbwasserverband Grazerfeld (AWV Grazerfeld) is an Austrian municipal wastewater association based in Wildon, Styria, responsible for wastewater collection, treatment, and disposal in the Grazerfeld region. The association celebrated its 50th anniversary in 2023 and operates a wastewater treatment plant (Abwasserreinigungsanlage) at its Wildon facility. It recently installed Austria's first solar fold-roof photovoltaic system over its treatment plant to achieve energy self-sufficiency.
- Industry
- Wastewater Treatment & Municipal Water Services
- Address
- Untere Aue 20, 8410 Wildon, Austria
- Founded
- 1973
Attack summary
Severity: high — The victim is a public municipal wastewater utility operating critical water/sanitation infrastructure; data has been confirmed published by the threat actor. Compromise and data publication of a critical infrastructure operator constitutes high severity, with potential exposure of operational data, employee records, and details relevant to public utility operations.LockBit 5 claims to have compromised AWV Grazerfeld and has published data (disclosed status: data_published), though no specific data size or ransom amount has been stated. The leak post excerpt references administrative operations, suggesting internal organisational and operational data may be at stake.
Data the group says was taken
AI dossier — extracted from the leak post- Administrative records
- Operational documents
- Internal communications
- Organisational management data
What the group claims
Verwaltung Unter dem Motto "Weg vom Kostenumleger und hin zum Dienstleister" hat sich die Geschäfts...
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

