Ransomware victim disclosure
← All victimsSprachakademie Rhein-Ruhr
Claimed by Storm · listed 3 hours ago
Status timeline
- ListedAug 27, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSprachakademie Rhein-Ruhr is a German language training provider based in Duisburg that has operated since 1995. They offer A1-C1 level German courses both in-person and online, including specialized programs for medical professionals, and operate as a certified telc examination center for language proficiency testing. Their services support international students and professionals seeking university admission and visa qualification in Germany.
- Industry
- Language Education & Professional Training
- Address
- Hansastraße 79, 47058 Duisburg, Germany
- Employees
- 11-50
- Founded
- 1995
Attack summary
Severity: low — The disclosed status is 'data_published' but no data inventory is specified in the leak post, no proof files are advertised, and no operational disruption is claimed. The post contains only a generic company description without evidence of exfiltration or encryption.The Storm group claims to have breached Sprachakademie Rhein-Ruhr and accessed company data. The leak post does not specify whether data was encrypted, exfiltrated, or both, nor does it detail the categories of data accessed.
What the group claims
Sprachakademie Rhein-Ruhr has been providing German language courses since 1995, aimed at individuals looking to study and build a life in Germany. They offer a range of courses from A1 to C1 levels, including specialized programs for medical professionals and online options. As a certified telc examination center, they facilitate language proficiency tests in accordance with the Common European Framework of Reference for Languages. Their services are designed to support clients in obtaining university access and visa acquisition in Germany. The company headquarters is located in Hansastraße 79, 47058 Duisburg, Germany. 11-50 Employees
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

