Ransomware victim disclosure
← All victimshep global GmbH
Claimed by Darkrace · listed 3 years ago
Status timeline
- Listed
Jun 4, 2023
- Data leaked
At a glance
- Group
- Darkrace
- Status
- Data leaked
- Country
- Japan
- Sector
- Energy & Utilities
- Listed on leak site
- Jun 4, 2023
About the victim
AI dossier — public-source company profilehep global GmbH is a German-headquartered company founded in 2008 that develops, builds, operates, and finances solar parks worldwide. The company has developed large-scale photovoltaic facilities with a combined capacity of approximately 1,310 MW peak and operates 18 solar projects from offices in Germany, Japan, and the USA. Its active pipeline for future projects comprises around 5,300 MW peak.
- Industry
- Solar Energy Development & Finance
- Founded
- 2008
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by the threat actor against a renewable energy infrastructure company with international operations, indicating confirmed exfiltration of significant business data. The energy sector and scale of operations elevate the impact, though no regulated PII or medical data is explicitly confirmed.Darkrace claims to have exfiltrated data from hep global GmbH and has published the data. No specific ransom demand or data size was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial data
- Solar project documentation
- Operational project records
- Business pipeline information
What the group claims
A partner for everything to do with solar energy. That’s hep. Since 2008. We develop, build, operate and finance solar parks. World-wide. For energy production that can do more than supply electricity. The large-scale photovoltaic facilities we have developed have a capacity of around 1,310 MW peak. From our sites in Germany, Japan and the USA we operate 18 solar projects ourselves. Our active pipeline for future projects comprises around 5,300 MW peak. (The number of solar parks in operation are up to date. All the other figures are updated every six months.)
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
