Ransomware victim disclosure
← All victimsthallos AG
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Germany
- Sector
- Technology
- Listed on leak site
- Mar 7, 2026
About the victim
AI dossier — public-source company profilethallos AG is a German financial and real estate services firm offering bank-independent financial advisory, real estate investment, project development, and property management. The company specialises in capital-investment-oriented properties — including residential, commercial, and heritage-listed buildings — primarily in the Stuttgart, Rhein-Main, and Munich metropolitan areas. Its group subsidiaries handle the full lifecycle from project development and renovation to rental management and structured financing.
- Industry
- Real Estate Investment, Development & Financial Advisory
Attack summary
Severity: medium — Disclosure status is marked 'data_published', suggesting data has been released, but the leak post content is unavailable and no proof files, data volume, or specific data categories are confirmed. The company handles financial advisory and real estate investment data for private individuals and institutional clients, which carries inherent sensitivity, but the absence of verifiable proof limits the assessment to medium.The Nightspire ransomware group claims an attack against thallos AG, with the disclosure status recorded as 'data_published'; however, the leak post content is currently unavailable, so specific claims regarding encryption or exfiltration cannot be verified from the post itself.
What the group claims
Data is not available now.
Sources
- Victim sitewww.thallos.ag
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

