Ransomware victim disclosure
← All victimsKreishandwerkerschaft Borken
Claimed by Rhysida · listed 2 hours ago
Status timeline
- ListedSep 20, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileKreishandwerkerschaft Borken is the official trade association and advocacy organization representing local craft enterprises (Handwerksbetriebe) in the Borken district of Germany. It serves as the collective voice and administrative body for artisan and skilled trades businesses in the region.
- Industry
- Trade Association / Craft Enterprises
- Address
- Borken district, Germany
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale: health information with diagnoses and disability classifications (German medical data protection), full employee PII (SSN-equivalent, IBANs, tax IDs), member financial data, and infrastructure credentials. Health and financial data of this scope and sensitivity triggers critical classification under GDPR and German data protection law.Rhysida claims to have exfiltrated 1.31 TB (1,382,523 files) from Kreishandwerkerschaft Borken, including health data with disability classifications and medical diagnoses, employee payroll records with tax IDs and bank account details, member financial information, credit checks, and full mail/database backups with infrastructure credentials (2FA secrets, S-FIRM code). The group is attempting to auction this data exclusively.
Data the group says was taken
AI dossier — extracted from the leak post- Health data (disability lists, GdB medical rulings with diagnoses)
- Sick leave and absence records
- Payslips with tax IDs and social-security numbers
- Staff rosters
- Signed employment contracts and terminations with CVs
- Member and creditor IBANs
- SCHUFA credit checks and court enforcement orders
- Exchange mail and SQL database backups
- 2FA secrets and S-FIRM infrastructure codes
What the group claims
The official trade association and advocacy organization representing local craft enterprises (Handwerksbetriebe) in the Borken district of Germany.
The leak post
captured from the group's siteThe Kreishandwerkerschaft Borken is the official trade association and advocacy organization representing local craft enterprises (Handwerksbetriebe) in the Borken district of Germany.1,382,523 files, 1.31 TBhealth data (disability lists with ID numbers, GdB medical ruling with diagnosis)sick leave, absence records, pension ruling2026 payslip (tax ID, social-security no., IBAN) and staff rostersigned contracts/terminations, CV with religionmember and creditor IBANsSCHUFA credit checks, court enforcement order, debtor affidavitMail and databases in full (Exchange, PST, SQL backups) + access/infrastructure slide (2FA secrets, S-FIRM code) With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! MPA Pharma GmbH is an internationally active, rapidly growing company specializing in the import and trade of high-quality pharmaceuticals, including both patented and generic products. 2,899,290 files, ~5.8 TBPharmaceutical companyCategories: accounting records and database backups, government audits (customs / corporate tax / …
Data the group says was taken
- health data
- disability lists with ID numbers
- GdB medical ruling with diagnosis
- sick leave records
- absence records
- pension ruling
- payslips
- tax IDs
- social security numbers
- IBANs
- staff rosters
- signed contracts
- CVs with religion
- member and creditor IBANs
- SCHUFA credit checks
- court enforcement orders
- debtor affidavits
- mail archives
- Exchange backups
- PST backups
- SQL backups
- 2FA secrets
- S-FIRM code
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

