Ransomware victim disclosure
← All victimsn-tree solutions Ticketsysteme GmbH
listed as n-tree.com · Claimed by ZaWoo · listed 22 hours ago
Status timeline
- ListedAug 30, 2026
- Data leakeddate unknown
At a glance
- Group
- ZaWoo
- Status
- Data leaked
- Country
- Austria
- Sector
- Technology
- Listed on leak site
- Aug 30, 2026
About the victim
AI dossier — public-source company profilen-tree solutions Ticketsysteme GmbH is an Austrian software and hardware company that develops visitor management, ticketing, access control, and reservation systems for leisure, cultural, and industrial facilities. Operating for over 25 years, they provide integrated solutions including point-of-sale systems, RFID/barcode entry controls, and online booking platforms.
- Industry
- Visitor Management & Ticketing Systems
Attack summary
Severity: medium — Data has been published and access is being restricted behind authentication, suggesting genuine exfiltration. However, without visibility into the actual file contents, data types, or volume, the sensitivity cannot be fully assessed. The victim is a B2B software/hardware vendor rather than a direct holder of consumer data, which moderates severity.ZaWoo claims to have compromised n-tree solutions' systems and is publishing exfiltrated data. The leak post provides minimal detail; the actual data contents and scope are obscured behind a login wall.
Data the group says was taken
AI dossier — extracted from the leak post- unspecified exfiltrated files
What the group claims
They develop software and hardware solutions mainly for visitor management and ticketing systems used by: swimming pools and wellness centers, museums and exhibitions, leisure parks, climbing gyms and fitness facilities, mountain railways and ski lifts, industrial visitor systems. Their main locations include: Bregenz, Austria (head office), Delitzsch, Germany, Heimberg, Switzerland, Riazzino, Switzerland/Italian region.
The leak post
captured from the group's sitePlease login to view files. After login, the directory tree will be loaded. Click to start, or Cancel to abort.
Sources
Source
Indexed 22 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

