Ransomware victim disclosure
← All victimsOnline Marketing Agency (Berlin)
Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedOct 3, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- Germany
- Sector
- Marketing/Advertising
- Listed on leak site
- Oct 3, 2026
About the victim
AI dossier — public-source company profileA digital marketing agency based in Berlin with additional offices in Dresden, Munich, and Cologne, Germany. Operating for more than twelve years, the agency manages national and international online projects for companies across diverse industries.
- Industry
- Online Marketing & Digital Advertising
- Address
- Berlin, Dresden, Munich and Cologne, Germany
- Employees
- 40+
Attack summary
Severity: high — Confirmed exfiltration of business-critical data including client projects, operations records, and employee personal data from a marketing agency; exposure of client intellectual property and operational information represents significant business harm.Rhysida claims to have exfiltrated business data from the agency. The leak post indicates encryption and data theft, with multiple data categories exposed.
Data the group says was taken
AI dossier — extracted from the leak post- Project files and client data
- Business operations records
- Internal communications
- Employee information
What the group claims
A Berlin-based online marketing agency with offices in Dresden, Munich and Cologne, specializing in national and international online projects for over twelve years with more than 40 employees.
The leak post
captured from the group's siteMat Bao Corporation offers a range of services including domain registration, cloud hosting, professional email solutions, and cloud server storage. Files: 746,108Data volume: 106.8 GBGovernment inspection materials - NEAC inspection decision No. 61/QD (29.04.2025) against the certification authority, working minutes naming state inspectors and company staff (through December 2025).Corporate core - GPKD business-registration documents bearing the owner's signature, shareholder records, tax commitments (January 2026).Personal data - national ID cards (CCCD) and employee passports with signatures, staff lists.Regulator correspondence - VNNIC, NEAC, the Government Cipher Committee (including RSA-1024 token vulnerabilities).Litigation and operations - the VINASEED dispute, internal investigations, operations-department mail. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! ElectroHeat industrial furnaces are used in manufacturing industries all over the world.Files: 1,723,527Data volume: 2,55 TBAll intellectual p…
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

