Ransomware victim disclosure
← All victimsSchaltbau
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Mar 5, 2026
- Data size
- 20 GB
About the victim
AI dossier — public-source company profileSchaltbau is a German manufacturer of electromechanical components and driver's desks for railway and industrial applications, founded in 1929. The company supplies safety-critical systems for rail services and also serves markets in renewable energy, e-mobility, and industrial automation. It is a well-established mid-to-large industrial group headquartered in Germany.
- Industry
- Electromechanical Components & Railway Systems Manufacturing
- Employees
- 1001-5000
- Founded
- 1929
Attack summary
Severity: critical — The exfiltration includes regulated PII (passport scans, personal identity documents) at scale alongside sensitive commercial and technical data from a safety-critical railway and industrial infrastructure supplier; 20 GB of data has been announced for imminent publication.Akira claims to have exfiltrated approximately 20 GB of corporate data from Schaltbau, with planned publication imminent. The stolen data reportedly includes employee passport scans and personal documents, project files, specifications, contracts, internal confidential files, and client documentation.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passport scans
- Personal identity documents
- Project files
- Technical specifications
- Contracts
- Internal confidential files
- Client documents
What the group claims
Schaltbau develops and manufactures electromechanical components and innovative driver's desks for railways and industry. Since 19 29, the company has been responsible for the safe operation of ra il services, and today the company protect systems in industrial applications for renewable energy, e-mobility, and automation. We will upload 20gb of corporate data soon. Employee passports an d other personal docs scans, lots of projects, specifications, co ntracts, internal confidential files, clients docs and so on.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

