Ransomware victim disclosure
← All victimsHofmann Fördertechnik GmbH
Claimed by Hunters · listed 1 year ago
Status timeline
- ListedApr 6, 2025
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Apr 6, 2025
About the victim
AI dossier — public-source company profileHofmann Fördertechnik GmbH is a German solutions provider in intralogistics, offering a broad portfolio of material handling equipment including forklifts, automated transport systems, cleaning robots, aerial work platforms, and racking systems. The company operates a fleet of over 1,400 rental devices and provides maintenance, financing, and consulting services to optimize customer logistics processes.
- Industry
- Material Handling & Intralogistics Equipment
Attack summary
Severity: high — Confirmed dual-action attack (encryption + exfiltration) with data published by the group. The company operates in critical logistics infrastructure serving manufacturing and warehouse operations. Lack of specific proof count or data inventory detail prevents 'critical' classification, but operational disruption to a logistics provider is significant.The hunters ransomware group claims to have both encrypted Hofmann Fördertechnik's systems and exfiltrated data. The group has published exfiltrated data but no specific details about the scope or nature of the compromised information are provided in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- customer data
- operational/systems data
What the group claims
Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

