Ransomware victim disclosure
← All victimsPlanungsgruppe M+M AG
Claimed by Aurora · listed 10 hours ago
Status timeline
- ListedAug 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Professional Services
- Listed on leak site
- Aug 17, 2026
About the victim
AI dossier — public-source company profilePlanungsgruppe M+M AG is a German professional services firm headquartered in Böblingen with approximately 432 employees across 10 offices in major German cities. The company specializes in architecture, urban planning, structural engineering, building physics, fire protection, BIM modelling, landscape planning, and interior design, having completed over 5,200 projects over decades of operation with annual revenue around €52 million.
- Industry
- Architecture & Urban Planning; Structural Engineering; Building Design Services
- Address
- Böblingen, Baden-Württemberg, Germany (headquarters); 10 offices across Germany
- Employees
- 432
Attack summary
Severity: critical — Confirmed exfiltration of regulated financial data (DATEV, SFirm, payroll), employee PII (HR, payroll), email archives, and 20 years of business records at scale (268 GB, 124,000 files). Financial and payroll data are subject to German data protection law; exposure represents significant regulatory and operational risk.Aurora claims to have exfiltrated two complete file servers (MMBB04, MMBB05) plus financial, banking, document management, email, and payroll systems. The dataset comprises approximately 268 GB across 124,000 files spanning 20 years (2006–2026), including DATEV financial archives, SFirm banking databases, ELO document management, Outlook email (PSTs), and HR/payroll records.
Data the group says was taken
AI dossier — extracted from the leak post- Financial processing archives (DATEV)
- Banking software databases (SFirm)
- Document management system (ELO)
- Email archives (Outlook PSTs)
- Payroll and HR data
- Project files and technical documentation
- File server backups (MMBB04, MMBB05)
What the group claims
Planungsgruppe M+M AG is a German Aktiengesellschaft headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices (Böblingen, Stuttgart, München, Nürnberg, Regensburg, Ingolstadt, Augsburg, Esslingen, Mannheim, Frankfurt). Annual revenue: approximately €52 million. The firm provides architecture, urban planning, structural engineering, building physics, fire protection, BIM, landscape planning, and interior design services. Over 5,200 projects completed across decades of operation. The exfiltrated dataset spans two complete file servers (MMBB04, MMBB05), plus the DATEV financial processing archives, SFirm banking software databases, the ELO document management system, Outlook email archives (PSTs), and payroll/HR data — a total of 268 GB across approximately 124,000 files, covering 2006 to 2026.
The leak post
captured from the group's sitePlanungsgruppe M+M AG is a German Aktiengesellschaft headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices (Böblingen, Stuttgart, München, Nürnberg, Regensburg, Ingolstadt, Augsburg, Esslingen, Mannheim, Frankfurt). Annual revenue: approximately €52 million. The firm provides architecture, urban planning, structural engineering, building physics, fire protection, BIM, landscape planning, and interior design services. Over 5,200 projects completed across decades of operation. The exfiltrated dataset spans two complete file servers (MMBB04, MMBB05), plus the DATEV financial processing archives, SFirm banking software databases, the ELO document management system, Outlook email archives (PSTs), and payroll/HR data — a total of 268 GB across approximately 124,000 files, covering 2006 to 2026.
Sources
Source
Indexed 10 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

