Ransomware victim disclosure
← All victimsBAVACAI
Claimed by MEDUSA LOCKER (aka BAVACAI · listed 3 months ago
Status timeline
- ListedMay 31, 2026
- Data leakeddate unknown
At a glance
- Status
- Data leaked
- Country
- Germany
- Sector
- Legal Services
- Listed on leak site
- May 31, 2026
- Records
- 8050 files
About the victim
AI dossier — public-source company profileBAVACAI is a German legal services firm operating in the Hesse region. The company handles civil litigation cases (GBA proceedings) across multiple jurisdictions including Darmstadt, Langen, and surrounding areas.
- Industry
- Legal Services
Attack summary
Severity: high — Confirmed exfiltration of 8,050 files containing sensitive legal case information, client identity data, and court proceedings. Legal privilege violations and significant personal data exposure of litigation parties.MEDUSA LOCKER claims to have encrypted BAVACAI's systems and exfiltrated approximately 8,050 files. The group has published a sample of case files and legal documents as proof of access.
Data the group says was taken
AI dossier — extracted from the leak post- Civil litigation case files (GBA proceedings)
- Client names and case details
- Court filings and legal documents
- Client correspondence
The group's post references roughly 10 proof files.
What the group claims
Victim identified as 'bapamai' on the leak site. Leaked files appear to be legal documents (GBA - Grundbuchamtsachen/land registry or court documents) related to various German locations including Gundernhausen-Darmstadt, Schwanheim, Bensheim, Ober-Roden, suggesting a German legal or notary firm.
The leak post
captured from the group's site⚠ Demo access — showing up to 10 files per folder. Full data will be available after publication. | | | | [(006-2023 N) GBA v. Gundernhausen-Darmstadt Blatt 2149 Wohlgemuth.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(006-2023%20N\)%20GBA%20v.%20Gundernhausen-Darmstadt%20Blatt%202149%20Wohlgemuth.doc) | | [(007-2023 N) Friedrich, Ubegl.mit Weiterleitung.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(007-2023%20N\)%20Friedrich,%20Ubegl.mit%20Weiterleitung.doc) | | [(007-2024 N) GBA v. Ober-Roden, AG Langen Hessen, Blätter 6142 u. 6214 Förster-R-.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(007-2024%20N\)%20GBA%20v.%20Ober-Roden,%20AG%20Langen%20Hessen,%20Bl%C3%A4tter%206142%20u.%206214%20F%C3%B6rster-R-.doc) | | | | [(009-2022 N) GBA Kusche (Rappe) -.doc](http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/bapamai/preview/\(009-2022%20N\)%20GBA%20Kusche%20\(Rappe\)%20-.doc) | | | [(011-2023 N) GBA v. Schwanheim Blatt 6258 (Werkmann).doc](http://t33zoj4qwv455fo…
Data the group says was taken
- legal documents
- court documents
Screenshot of the leak post

Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

