Ransomware victim disclosure
← All victimsDer Paritätische NRW
listed as paritaet-nrw.org · Claimed by Safepay · listed 2 days ago
Status timeline
- ListedJul 27, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Germany
- Sector
- Professional Services
- Listed on leak site
- Jul 27, 2026
About the victim
AI dossier — public-source company profileDer Paritätische NRW is a major social services umbrella organization headquartered in Wuppertal, Germany. It represents approximately 3,100 legally independent member organizations operating more than 7,000 social institutions and services across North Rhine-Westphalia.
- Industry
- Social Services & Welfare Advocacy
- Address
- Wuppertal, Germany
- Employees
- 3100+
Attack summary
Severity: high — Confirmed data publication by ransomware group targeting a large social services organization with 3,100+ member institutions. Likely exposure of organizational, institutional, and potentially beneficiary-related data affecting thousands of social service delivery organizations.The SafePay group claims to have breached Der Paritätische NRW and exfiltrated data. The group has published data on their leak site, though specific details of the attack vector and data scope are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- organizational records
- member data
- institutional information
What the group claims
Headquartered in Wuppertal, the organization represents approximately 3,100 legally independent member organizations operating more than 7,000 social institutions and services …
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

