Ransomware victim disclosure
← All victimsCiarus Technologies
listed as Ciarus · Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Germany
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileCiarus Technologies is a software development company headquartered in Berlin, Germany. They offer custom software development, web and mobile app development, SaaS development, QA, SEO, DevOps, and IT outsourcing services. The company targets businesses seeking tailored IT solutions and dedicated development teams.
- Industry
- Custom Software Development & IT Services
- Address
- Hochstraße 15C, 13357 Berlin, Germany
Attack summary
Severity: medium — Data has been published (not merely listed), indicating confirmed exfiltration, but no specific data volume, regulated/sensitive personal data, or operational disruption to critical infrastructure is evidenced; the victim is a small software services firm with no stated scale of sensitive data.The group 'thegentlemen' claims to have attacked Ciarus Technologies and has published data (disclosed status: data_published), though no specific ransom amount or data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal data
- Client project files
- Business communications
What the group claims
ciarus.de zoominfo.com/c/ciarus/1324145982 Ciarus Technologies is a software development company based in Germany that specializes in custom software development, web and mobile app development, IT outsourcing, and DevOps services. They cater to businesses looking for tailored IT solutions to enhance their competitiveness in the digital landscape. With a focus on exceptional customer service and technical expertise, Ciarus aims to help clients bring their ideas to life through reliable and cost-effective technology
Sources
- Victim siteciarus.de
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

