Ransomware victim disclosure
← All victimsATG (Advanced Testing Group)
listed as atg.cz · Claimed by Warlock · listed 7 months ago
Status timeline
- ListedNov 6, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- Czechia
- Sector
- Technology
- Listed on leak site
- Nov 6, 2025
About the victim
AI dossier — public-source company profileATG is a Czech-based company and one of the largest NDT-oriented companies worldwide, with approximately 30 years of history in the field of non-destructive testing. The company provides complete solutions for NDT by offering both products (ET, FPI, MPI, UT, RT systems and equipment) and services (testing, inspection, personnel qualification, consultancy) across industries including aerospace, automotive, energy, and railways. ATG operates as a group with subsidiaries including ATG Slovakia and LA composite.
- Industry
- Non-Destructive Testing (NDT) Equipment & Services
Attack summary
Severity: high — Data has been confirmed published (data_published status) by the threat actor. ATG serves aerospace, automotive, energy, and railways sectors with NDT qualification and certification services; exfiltrated data could include proprietary testing methodologies, customer/client records, personnel qualification data, and sensitive industrial inspection results. The industrial and safety-critical nature of the sectors served elevates severity.The Warlock ransomware group claims a successful attack on ATG (atg.cz) with the disclosure status marked as data_published, indicating data has been exfiltrated and published. No further description of the attack vector, encrypted systems, or specific data categories was provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Published company data (type unspecified)
What the group claims
No description provided.
Sources
- Victim siteatg.cz
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

