Ransomware victim disclosure
← All victimsINTERSPA Betriebsverwaltungsgesellschaft
Claimed by Qilin · listed 3 months ago
Status timeline
- ListedJun 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Germany
- Sector
- Business Services
- Listed on leak site
- Jun 5, 2026
About the victim
AI dossier — public-source company profileINTERSPA is a German company specializing in the development, construction, and profitable operation of thermal baths and leisure facilities. Operating under the Wonnemar brand at six locations across Germany, they offer consulting, architectural design, and operational management services for public-private partnership spa and family bath projects.
- Industry
- Leisure & Spa Facilities Management
- Address
- Löffelstraße 44, 70597 Stuttgart, Germany
Attack summary
Severity: medium — Data has been published by the ransomware group, indicating confirmed exfiltration, but without visibility into the leak post content or proof artifacts, the sensitivity and scale of exposed data cannot be assessed. The company operates leisure facilities with potential access to customer PII and operational data, but no regulated sectors (healthcare, finance) are directly indicated.The Qilin group claims to have conducted an attack on INTERSPA and published data. No specific details on the nature of the breach (encryption vs. exfiltration) or data types are provided in the available post excerpt.
What the group claims
N/A
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

