Ransomware victim disclosure
← All victimsZurflüh-Feller
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- France
- Sector
- Manufacturing
- Listed on leak site
- Feb 2, 2026
- Data size
- 66 GB
About the victim
AI dossier — public-source company profileZurflüh-Feller is a French manufacturer specializing in components for roller shutters and building closure systems, founded in 1920. The company focuses on logistics optimization and technical partnerships, providing tailored support and timely delivery to its clients.
- Industry
- Building Components & Roller Shutter Systems Manufacturing
- Founded
- 1920
Attack summary
Severity: critical — Confirmed exfiltration of 66 GB including regulated PII (passports, national ID cards) at employee scale, combined with sensitive financial and legal documents, and data has been disclosed/published.Akira claims to have exfiltrated 66 GB of corporate data from Zurflüh-Feller, including employee identity documents (passports, ID cards), detailed financial records, confidential files, contracts, agreements, and NDAs, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee identification cards
- Detailed financial records
- Confidential corporate files
- Contracts and agreements
- NDAs
What the group claims
Zurflüh-Feller is a leading French manufacturer of components for roller shutters, specializing in systems and solutions for build ing closures since 1920. The company is committed to optimizing l ogistics and providing technical partnerships, ensuring timely de livery and tailored support for its clients. We will upload 66gb of corporate data soon. Employee documents (p assport, identification cards), detailed financials, confidential files, contracts and agreements, NDAs, etc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

