Ransomware victim disclosure
← All victimsWestfälische Stahlgesellschaft
listed as ws-stahl.eu · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedJul 5, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Jul 5, 2024
About the victim
AI dossier — public-source company profileWestfälische Stahlgesellschaft is a German steel manufacturer and trading group founded in 1919, specializing in bright steel, rolled and forged bar steel, and precision steel tubes. Operating from multiple locations including Plettenberg, Löhne, and Stuhr-Brinkum, the company maintains over 60,000 tonnes of inventory and serves global customers with just-in-time delivery.
- Industry
- Steel Manufacturing & Distribution
- Address
- Plettenberg, Germany
- Founded
- 1919
Attack summary
Severity: medium — Data has been published by the threat actor, indicating confirmed exfiltration. However, the post lacks specific proof files, screenshots, or detailed inventory of sensitive data types. No regulated data (PII at scale, financial records, medical data) is explicitly mentioned. Severity is elevated from low due to confirmed publication but remains medium pending evidence of sensitive data volume.LockBit3 claims to have attacked Westfälische Stahlgesellschaft and published data from the incident. The leak post references the company's public website content, indicating data exfiltration, though specific details of encrypted systems or data categories are not elaborated in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Business information from public website
- Potential internal documents
- Customer or supplier data (inferred)
What the group claims
Passion for steel. Since 1919 Bright steel. Bar steel. Steel tubes. Pre-processing. Materials expertise. The Westfälische Stahlgesellschaft group of companies comprises trading companies in various regions of Germany and, with the Plettenberg drawi...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

