Ransomware victim disclosure
← All victimsKrause & Co
listed as krauseundco · Claimed by Incransom · listed 2 months ago
Status timeline
- ListedApr 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Germany
- Sector
- Business Services
- Listed on leak site
- Apr 25, 2026
About the victim
AI dossier — public-source company profileKrause & Co is a German civil engineering and construction company offering a broad range of services including renovation and restoration of buildings, road and path construction, sewer construction, pipeline construction for gas, water, and district heating, plant construction, and trade in building materials. The company also provides engineering and specialized civil engineering services such as concrete restoration. It operates in Germany and serves clients across multiple construction and infrastructure segments.
- Industry
- Civil Engineering & Construction
Attack summary
Severity: medium — Data has been published by the group, confirming some level of exfiltration, but no specific sensitive regulated data categories (e.g. PII at scale, medical, financial) are confirmed, and data volume is unknown; the victim is a mid-sized civil engineering firm in Germany.The incransom group claims to have attacked Krause & Co and has published data (disclosed status: data_published), indicating exfiltration of company data, though the specific volume and exact data categories have not been detailed in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Business documents
- Engineering project files
- Company operational data
What the group claims
Provision of civil engineering services, renovation and restoration of all types of buildings, road and path construction, sewer construction, pipeline construction for gas, water, and district heating, plant construction, engineering services, specialized civil engineering services, concrete restoration, trade in building materials, and all activities conducive to furthering the company’s purpose.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

