Ransomware victim disclosure
← All victimsLUX Automation GmbH
listed as Control & Automation technology - LUX Automation · Claimed by Monti · listed 3 years ago
Status timeline
- ListedMay 3, 2023
- Data leakeddate unknown
At a glance
- Group
- Monti
- Status
- Data leaked
- Country
- Germany
- Sector
- Technology
- Listed on leak site
- May 3, 2023
About the victim
AI dossier — public-source company profileLUX Automation GmbH, founded in 2008 as a successor to BEA Elektrotechnik und Automation GmbH (est. 1899), is a 100% subsidiary of SMS group GmbH specialising in integrated automation technology, drive technology, process automation, and industrial plant engineering. The company serves the metals and heavy industry sectors. In 2025, LUX Automation was partly integrated into SMS group's lifecycle services, with its office relocated to the SMS Campus in Mönchengladbach, Germany.
- Industry
- Industrial Automation & Plant Engineering
- Address
- SMS Campus, Mönchengladbach, Germany
- Founded
- 2008
Attack summary
Severity: high — Data has been published (not merely listed), indicating confirmed exfiltration. LUX Automation is a subsidiary of a major industrial group (SMS group GmbH) involved in critical manufacturing infrastructure, and the disclosed data likely includes sensitive business, engineering, and operational information.The Monti ransomware group claims to have attacked LUX Automation and has reached the data_published stage, indicating exfiltration and publication of stolen data. No specific data volume or ransom demand was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Automation technology project files
- Industrial plant engineering data
- Business operational data
- Potentially employee/contact information
What the group claims
lux-automation.com For drive, regulation or control technology: LUX Automation is your expert when it comes to automation technology and process automation.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

