Ransomware victim disclosure
← All victimsCPU Softwarehouse AG
listed as cpu-ag.com · Claimed by Safepay · listed 5 hours ago
Status timeline
- ListedAug 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Aug 3, 2026
About the victim
AI dossier — public-source company profileCPU Softwarehouse AG is a German software and consulting firm founded in 1981, headquartered in Friedberg, Bavaria. With over 40 years of experience, the company specializes in developing customized software solutions, consulting services, and IT support primarily for the banking sector, including process optimization, digitalization strategies, and business process management.
- Industry
- Software Development & IT Consulting, Specialized Banking Software
- Address
- Friedberg, Bavaria, Germany
- Founded
- 1981
Attack summary
Severity: medium — Data has been published by the ransomware group (disclosed_status: data_published), indicating confirmed exfiltration. However, no specific details about data sensitivity, volume, or nature are evident from the leak post excerpt. The target is a software/consulting firm (not critical infrastructure), but the banking sector focus and 40+ years of operations suggest potential access to sensitive financial or client data.The SafePay ransomware group claims to have attacked CPU Softwarehouse AG and published data from the breach. The group has disclosed the attack but specific details regarding encryption, exfiltration scope, or data categories are not provided in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate documents
- Business data
What the group claims
Founded in 1981 and headquartered in Friedberg, Bavaria, the company has more than four decades of experience developing specialized software …
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

