Ransomware victim disclosure
← All victimsHungarian Development Policy Company
Claimed by Rhysida · listed 3 days ago
Status timeline
- ListedSep 2, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileA Hungarian government or quasi-governmental entity responsible for planning and implementing development programs funded by EU and domestic sources. No public website or further identifying information is available.
- Industry
- Government/Public Administration - Development Policy
Attack summary
Severity: critical — Confirmed large-scale exfiltration of highly sensitive government data including state secrets, classified materials, personnel PII (16,389 emails, 11,963 phone numbers, 12,076 individuals), credentials in plaintext, legal/disciplinary case files, and KRITIS (critical infrastructure) vulnerability analyses. The post references declassified correspondence, state security police misconduct cases, and Bundesrat protocols—indicating compromise of government administrative and potentially national-seRhysida claims to have exfiltrated 9.06 million files totalling approximately 5.79 TB, including SQL databases, personnel records, financial statements, and sensitive government data. The post indicates encryption of systems and extraction of confidential materials related to state administration and policy implementation.
Data the group says was taken
AI dossier — extracted from the leak post- SQL databases
- Personnel files (Personalakten)
- Financial statements and payroll records
- Government supervisory documents
- Contracts and NDAs
- Personal identification documents (passports, ID cards)
- Email addresses and contact information
- Credentials and passwords in plaintext
- Legal and disciplinary case files
- State secrets and classified-material handling records
- Vulnerability analyses
- Backup of CRM system with customer and deal data
- KYC/AML documentation
What the group claims
A key player in Hungarian development policy that participates in the planning and implementation of development programs based on EU and domestic funds.
The leak post
captured from the group's siteAs a key player in Hungarian development policy, our Company participates in the planning and implementation of development programs based on certain EU and domestic funds. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! 9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total capacity 5.79 TBArchive scale: ~1.44 million files scanned; by category � Maps/Geo 124,823, Legal/complaints 77,939, Financial 55,553, Contracts 46,522, HR 27,299,Government supervisory 13,142, Confidential 11,7…
Data the group says was taken
- development program documents
- EU and domestic fund related data
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

