Ransomware victim disclosure
← All victimsinfoniqa.com
Claimed by Warlock · listed 10 months ago
Status timeline
- ListedAug 18, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- Austria
- Sector
- Technology
- Listed on leak site
- Aug 18, 2025
About the victim
AI dossier — public-source company profileInfoniqa is a DACH-region HR, payroll, and finance software provider serving over 40,000 customers and 6+ million end-users. The company offers cloud-based solutions for personnel management, payroll processing, and accounting, with 1,200 experts across 26 locations in Germany, Austria, and Switzerland. Founded over 55 years ago, Infoniqa specializes in mid-market compliance and automation.
- Industry
- HR, Payroll & Finance Software (SaaS)
- Address
- 26 standorte in Deutschland, Österreich und der Schweiz (multi-location DACH region)
- Employees
- 1200
- Founded
- 1989
Attack summary
Severity: critical — Confirmed exfiltration and publication of 165 GB of sensitive data including employee PII, financial records, and customer databases (HR/CRM/SaaS) from a software vendor serving 40,000+ clients and 6+ million users. Breach of a service provider creates cascading risk to downstream customers.The Warlock group claims to have exfiltrated 165 GB of data from Infoniqa, including internal documents, financial records, employee information, CRM database, HR database, and SaaS customer database. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- internal documents
- financial documents
- employee information
- CRM database
- HR database
- SaaS database
What the group claims
165g data, including internal documents, financial documents, employee information, CRM database, HR database, SaaS database
Sources
- Victim siteinfoniqa.com
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

