Ransomware victim disclosure
← All victimsBAVACAI
Claimed by MEDUSA LOCKER (aka BAVACAI · listed 18 hours ago
Status timeline
- Listed
May 31, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- DE
- Sector
- Legal Services
- Listed on leak site
- May 31, 2026
- Records
- 8050 files
What the group claims
Victim identified as 'bapamai' on the leak site. Leaked files appear to be legal documents (GBA - Grundbuchamtsachen/land registry or court documents) related to various German locations including Gundernhausen-Darmstadt, Schwanheim, Bensheim, Ober-Roden, suggesting a German legal or notary firm.
The leak post
captured from the group's site⚠ Demo access — showing up to 10 files per folder. Full data will be available after publication. | | | | [(006-2023 N) GBA v. Gundernhausen-Darmstadt Blatt 2149 Wohlgemuth.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(006-2023%20N\)%20GBA%20v.%20Gundernhausen-Darmstadt%20Blatt%202149%20Wohlgemuth.doc) | | [(007-2023 N) Friedrich, Ubegl.mit Weiterleitung.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(007-2023%20N\)%20Friedrich,%20Ubegl.mit%20Weiterleitung.doc) | | [(007-2024 N) GBA v. Ober-Roden, AG Langen Hessen, Blätter 6142 u. 6214 Förster-R-.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(007-2024%20N\)%20GBA%20v.%20Ober-Roden,%20AG%20Langen%20Hessen,%20Bl%C3%A4tter%206142%20u.%206214%20F%C3%B6rster-R-.doc) | | | | [(009-2022 N) GBA Kusche (Rappe) -.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(009-2022%20N\)%20GBA%20Kusche%20\(Rappe\)%20-.doc) | | | [(011-2023 N) GBA v. Schwanheim Blatt 6258 (Werkmann).doc](http://t33zoj4qwv455fo…
Data the group says was taken
- legal documents
- court documents
Screenshot of the leak post

Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
