Ransomware victim disclosure
← All victimsSW Automatisierung GmbH
listed as www.swautomation.at · Claimed by Lynx · listed 4 months ago
Status timeline
- Listed
Jan 6, 2026
- Data leaked
At a glance
- Group
- Lynx
- Status
- Data leaked
- Country
- Austria
- Sector
- Manufacturing
- Listed on leak site
- Jan 6, 2026
About the victim
AI dossier — public-source company profileSW Automatisierung GmbH is an Austrian manufacturer based in the Salzburger Land region with over 50 years of experience in electrical engineering, automation, and mechanical engineering. The company specialises in fully automated wire assembly machines (Wire Terminals) for control cabinet construction, sold under the brand SW WireTerminal. Their products automate wire cutting, stripping, crimping, and labelling and are ISO 9001:2015 certified.
- Industry
- Industrial Automation & Electrical Engineering Equipment Manufacturing
- Address
- Salzburger Land, Austria
Attack summary
Severity: high — Data has been published by the threat actor, confirming exfiltration of business data from a manufacturing company. While no regulated personal data at scale is explicitly confirmed, the published status and likely presence of proprietary engineering, customer, and operational data warrants a high severity rating.The Lynx ransomware group claims an attack on SW Automatisierung GmbH and has published data (disclosed status: data_published), indicating exfiltration of company data. No ransom amount or data size was specified in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Company business data
- Potentially internal engineering/manufacturing files
- Potentially customer and order records
What the group claims
sw-wireterminal.com
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
