Ransomware victim disclosure
← All victimsBender GmbH Tribunenbau
listed as Bender Tribunenbau · Claimed by Lamashtu · listed 24 hours ago
Status timeline
- ListedOct 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Lamashtu
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Oct 5, 2026
About the victim
AI dossier — public-source company profileBender GmbH Tribunenbau is a German manufacturer and rental provider of mobile and permanent grandstands, stages, podiums, and temporary event structures. Operating for over 70 years, the company serves major sporting events (Formula 1, MotoGP, World Cup skiing) and cultural events across Europe and globally, with TÜV-certified designs meeting international safety standards.
- Industry
- Event Infrastructure & Temporary Structures Manufacturing
Attack summary
Severity: low — The disclosure is listed as 'data_published' but the leak post excerpt provides no proof files, screenshots, or specific data inventory. No operational impact is stated. Without evidence of actual data exfiltration or encryption impact, and given the minimal detail in the post, severity cannot exceed low.The lamashtu group claims to have conducted an attack on Bender GmbH Tribunenbau. The leak post does not specify whether data was encrypted, exfiltrated, or both, nor does it detail what data categories are at stake.
What the group claims
Bender GmbH Tribunenbau is a German manufacturer of mobile and permanent grandstands, stages, podiums and temporary structures for events. It designs, rents, sells and services tribunes for stadiums, festivals and concerts.
Sources
Source
Indexed 24 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

