Ransomware victim disclosure
← All victimsSehlmann Fensterbau GmbH
listed as Newman & Marquez · Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 9, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSehlmann Fensterbau GmbH is a German company based in the Hamburg metropolitan area specializing in wooden and wood-metal windows. They provide comprehensive services covering consultation, planning, production, and installation for new constructions and renovation projects.
- Industry
- Windows & Doors Manufacturing (Wood & Wood-Metal)
- Address
- Hamburg metropolitan area, Germany
Attack summary
Severity: critical — The threat actor claims exfiltration of 95 GB of data containing large volumes of regulated PII including identity documents (passports, DLs, visas), financial data (credit cards), and sensitive legal records for both employees and clients at scale.Akira claims to have exfiltrated approximately 95 GB of corporate data, including employee and client personal files (passports, driver's licenses, death certificates, visas, credit cards), financial records, and legal documents such as court files, police reports, and lawsuit records.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal files
- Client passports
- Client driver's licenses
- Death certificates
- Visas
- Credit card information
- Financial records
- Court files
- Police reports
- Hearing records
- Lawsuit documents
What the group claims
Sehlmann Fensterbau GmbH specializes in wooden and wood-metal win dows in the Hamburg metropolitan area. They offer optimal window solutions for innovative new constructions and stylish renovation s, providing services from consultation and planning to productio n and installation. We will upload 95gb of corporate data soon. Employee personal fil es, large amount of client personal files (passports, DLs, death certs, visas, credit cards and other files), financials, court fi les, police reports, hearings, lawsuits and other files, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

