Ransomware victim disclosure
← All victimsHillmann Consulting
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- Germany
- Sector
- Business Services
- Listed on leak site
- Jan 29, 2026
- Data size
- 116 GB
About the victim
AI dossier — public-source company profileHillmann Consulting is a nationwide construction consulting and due diligence company based in Germany. The firm specialises in planning, managing, and executing construction projects, offering services including environmental health and safety, due diligence and remediation management, energy consulting, and construction services.
- Industry
- Construction Consulting & Due Diligence
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (passports, SSNs, driver's licences for approximately 250 employees) combined with sensitive business data (financials, NDAs, HR files) totalling 116 GB, with data publication imminent.Akira claims to have exfiltrated 116 GB of corporate data from Hillmann Consulting, including employee personal identity documents (driver's licences, passports, SSNs), contracts and agreements, financial records, HR files, confidential files, and NDAs, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee driver's licences (~250)
- Passports
- Social Security Numbers (SSNs)
- Contracts and agreements
- Financial records
- HR files
- Confidential files
- NDAs
What the group claims
Hillmann Consulting is a nationwide construction consulting and d ue diligence company that specializes in planning, managing, and executing construction projects. They offer a wide range of servi ces including environmental health and safety, due diligence and remediation management, energy consulting, and construction servi ces. We will upload 116gb of corporate data soon. Employees' data (250 DLs, passports, SSNs and so on), contracts and agreements, fina ncials, HR files, confidential files, NDAs and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

