Ransomware victim disclosure
← All victimsGILDE Handwerk Macrander GmbH & Co. KG
Claimed by Aurora · listed 4 hours ago
Status timeline
- ListedAug 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Aug 4, 2026
About the victim
AI dossier — public-source company profileGILDE Handwerk Macrander GmbH & Co. KG is a family-owned German Mittelstand wholesale group headquartered in Bocholt, North Rhine-Westphalia. It operates across multiple brands (GILDE Handwerk, Fink Living, HAKU Möbel) with 50+ legal entities spanning Germany, Austria, the Netherlands, France, the UK, and Hong Kong, serving the gifts, home accessories, and furniture sectors.
- Industry
- Wholesale Trade – Gifts, Home Accessories & Furniture
- Address
- Bocholt, Nordrhein-Westfalen, Germany
- Employees
- 400–900
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (148+ identity documents, 400–1000 individuals' tax IDs, SSNs, bank details), 20 years of sensitive financial records for a multinational group, and digital tax credentials enabling fraudulent VAT/income tax filings. Data spans executives, employees, and family members across multiple jurisdictions.Aurora claims to have exfiltrated comprehensive corporate and personal data. The group states it obtained 148+ employee/director identity documents, digital tax credentials for 50+ entities, full payroll records spanning 2006–2025 for 400–1000 individuals, 20 years of consolidated financial records, and 1,800+ inventory/commercial databases.
Data the group says was taken
AI dossier — extracted from the leak post- personal ID documents (Personalausweise, passports, driver licences, marriage certificates)
- ELSTER tax certificates (50+ entities)
- employee payroll records (2006–2025)
- tax IDs and social security numbers
- bank account details
- sick notes and disciplinary records
- consolidated financial records (2004–2025)
- balance sheets and P&L statements
- loan documentation and shareholder agreements
- access databases (inventory, customer lists, supplier terms, pricing)
- order history
What the group claims
[wholesale] GILDE Handwerk Macrander GmbH & Co. KG is a family-owned German Mittelstand group headquartered in Bocholt, Nordrhein-Westfalen. The GILDE Gruppe operates across wholesale trade in gifts, home accessories, and furniture through brands including GILDE Handwerk, Fink Living, and HAKU Möbel, with 50+ legal entities spanning Germany, Austria, the Netherlands, France, the UK, and Hong Kong. The exposed material includes: <censored> 148+ personal ID document scans — Personalausweise (national ID cards), Reispässe (passports), Führerscheine (driver's licences), and Heiratsurkunden (marriage certificates) for employees, directors, and family members. Names range from warehouse staff to the CEO. ELSTER tax certificates for 50+ entities — the digital keys for filing tax returns with the German Finanzamt, plus personal certificates for directors and family members. Enables fraudulent VAT returns and income tax filings. <censored> Full employee payroll records (2006–2025) — tax IDs (Steuer-IDs), social security numbers, bank accounts, salary details, sick notes (Krankmeldungen), and disciplinary records for an estimated 200–400 current and 200–500 former employees across all entities. 20 years of consolidated financial records — balance sheets, P&L statements, bank reconciliations, loan documentation, shareholder agreements, and capital contribution records for the entire group from 2004 to 2025. 1,800+ Access databases — inventory valuations, customer lists, supplier terms, product pricing, and order history spanning the entire commercial operation.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

