Ransomware victim disclosure
← All victimsKreishandwerkerschaft Borken
Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedSep 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Rhysida
- Status
- Data leaked
- Country
- Germany
- Sector
- Professional Services
- Listed on leak site
- Sep 19, 2026
About the victim
AI dossier — public-source company profileKreishandwerkerschaft Borken is a chamber of trades (Handwerkskammer) serving the Borken district in North Rhine-Westphalia, Germany. It represents over 1,000 member craft businesses and provides apprenticeship placement, legal counsel, debt collection, and continuing education services to member firms across various trades.
- Industry
- Trade Association & Vocational Services
- Address
- Hindenburgallee 17, 48683 Ahaus, Germany
Attack summary
Severity: medium — Confirmed operational disruption to a non-critical trade association serving regional craft businesses. No exfiltration of sensitive personal data or regulated information is publicly claimed. The leak post itself contains minimal detail; severity is based on encryption-only impact with no proof files published.Rhysida claims to have compromised the organization's IT systems. The public website confirms operational disruption, stating the EDV system was hacked and computers were expected to be non-functional until 24 September 2026. No data exfiltration is claimed in the leak post excerpt, and no proof files are advertised.
Data the group says was taken
AI dossier — extracted from the leak post- Member business directory
- Apprenticeship records
- Internal communications
- Administrative systems data
What the group claims
Kreishandwerkerschaft Borken
Sources
- Victim sitekh-borken.de
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

