Ransomware victim disclosure
← All victimsSehlmann Fensterbau
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Apr 9, 2026
About the victim
AI dossier — public-source company profileSehlmann Fensterbau GmbH is a German company specialising in the manufacture of wooden and wood-metal windows, operating in the Hamburg metropolitan area. The company provides end-to-end services covering consultation, planning, production, and installation for both new constructions and renovations.
- Industry
- Wooden & Wood-Metal Window Manufacturing
- Address
- Hamburg metropolitan area, Germany
Attack summary
Severity: high — Confirmed exfiltration of 44 GB of data including regulated personal identity documents (passports, DLs, national IDs) constituting PII, alongside financial and business records. The data is described as pending publication, indicating imminent exposure of sensitive employee information.Akira claims to have exfiltrated approximately 44 GB of corporate data from Sehlmann Fensterbau GmbH, including employee personal identity documents (passports, driving licences, EU IDs), financial records, and project files, with publication of the data stated as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driving licences
- EU identity cards
- Financial records
- Project files
- Corporate data (general)
What the group claims
Sehlmann Fensterbau GmbH specializes in wooden and wood-metal win dows in the Hamburg metropolitan area. They offer optimal window solutions for innovative new constructions and stylish renovation s, providing services from consultation and planning to productio n and installation. We will upload 44gb of corporate data soon. Employee personal fil es (passports, DLs, EU IDs and other files), financials, lots of project files, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

