Ransomware victim disclosure
← All victimsHagen Rosskopf
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 16, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileHagen Rosskopf is a boutique law firm based in Germany specialising in personal injury law, with a particular niche in representing injured cyclists. The firm handles client legal matters including court proceedings and associated documentation.
- Industry
- Personal Injury Law (Cycling Niche)
Attack summary
Severity: critical — The claim involves confirmed exfiltration of highly regulated personal data at scale — including health information, government-issued identity documents (passports, DLs), and legally privileged client files — all of which constitute sensitive PII and potentially special-category data under GDPR.Akira claims to have exfiltrated corporate and client data from Hagen Rosskopf and states the data will be uploaded imminently; the stolen data reportedly includes clients' passports, driving licences, health information, confidential legal files, court documents, police reports, and employee records.
Data the group says was taken
AI dossier — extracted from the leak post- Client passports
- Client driving licences
- Client health information
- Confidential legal files
- Court documents
- Police reports
- Employee files
What the group claims
A fast paced, boutique law firm that specializes in personal inju ry with a niche in representing injured cyclists. We will upload corporate data soon. Clients' personal information (passports, DLs, health information and so on), confidential leg al files, court docs, police reports, employee files, etc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

