Ransomware victim disclosure
← All victimsMuseum für Naturkunde
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedNov 29, 2023
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileMuseum für Naturkunde Berlin (Natural History Museum Berlin) is a publicly funded natural history museum and research institution located in Berlin, Germany. It holds one of the world's largest natural history collections, assembled over more than two centuries, and conducts scientific research across palaeontology, zoology, mineralogy, and related fields. The museum is affiliated with Humboldt-Universität zu Berlin and attracts hundreds of thousands of visitors annually.
- Industry
- Natural History Museum & Scientific Research
- Address
- Invalidenstraße 43, 10115 Berlin, Germany
- Employees
- 201-500
- Founded
- 1810
Attack summary
Severity: high — Data has been published by the threat actor against a publicly funded scientific and cultural institution, indicating confirmed exfiltration. The institution handles research data, staff PII, and sensitive administrative records; publication of such data from a heritage/government-affiliated body constitutes significant harm even absent explicit volume figures.The Snatch ransomware group claims to have attacked Museum für Naturkunde Berlin and has published data (disclosed status: data_published), though the leak post excerpt provides no specific details on the volume of data exfiltrated or whether systems were also encrypted.
Data the group says was taken
AI dossier — extracted from the leak post- Internal institutional documents
- Research data
- Staff/personnel records
- Administrative files
What the group claims
The Museum für Naturkunde Berlin has a long and eventful history - it has seen days of glory and survived crises. The collections that were brought together over more than two centuries from all over the world created a treasure trove of knowledge.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

