Ransomware victim disclosure
← All victimsVereinigte Stadtwerke GmbH
listed as Vereinigte-stadtwerke · Claimed by Payoutsking · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Payoutsking
- Status
- Data leaked
- Country
- Germany
- Sector
- Energy
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profileVereinigte Stadtwerke GmbH is a German municipal utility company (Stadtwerke) operating under the domain vereinigte-stadtwerke.de. Such entities typically provide electricity, gas, water, and district heating services to regional customers in Germany. The company operates as a GmbH (limited liability company), consistent with the common structure of German communal utility providers.
- Industry
- Municipal Utilities & Energy Supply
Attack summary
Severity: high — The victim is a municipal utility operator in Germany, classifying it as critical infrastructure. The disclosure status is 'data_published', indicating data has already been released, and energy-sector utilities typically hold operational, financial, and customer PII data. Even without explicit data inventory details, confirmed publication against a critical infrastructure target warrants a high severity rating.The ransomware group PayoutsKing claims to have exfiltrated and/or encrypted data from Vereinigte Stadtwerke GmbH, with the disclosure status listed as 'data_published'. No specific data volume or ransom amount was stated in the leak post for this victim.
Original description
AI-summarised, not from the leak postVereinigte Stadtwerke is a German utility company that supplies electricity, natural gas, and water to its customers. Apart from these, the company also offers telecommunication services including Internet and fixed network. It primarily serves residents and businesses in the Northern Germany region. The company was founded in 2012 as a merger of several municipal utilities to increase efficiency and service quality.
The leak post
captured from the group's sitePayoutsKing PayoutsKing Blog News About Partnership Welcome PK MAIN TOX: 535F403A2EA2DC71A392E18D7DB77FEF70845C0B7E5B9114CD30D301870304379C3547E324E2 Company Create Website Country Revenue Employees Actions Data Views Status H****l 2026-04-21 t****.com USA $786M ** Exfiltrated 860GB 0 Declared 1d 02:08 F****p 2026-04-14 fl****.com USA $2.7B ** Exfiltrated & Encrypted 1.1TB 0 Declared 1d 02:08 H****o 2026-04-01 has****.com USA $TBD ** Exfiltrated & Encrypted 4.8TB 0 Declared 1d 02:08 A****y 2026-03-31 ape****.com USA $309M ** Exfiltrated & Encrypted 3TB 0 Declared 2d 00:04 NTN Bearing Corporation of America 2026-04-24 ntnamericas.com USA $1.5B 4700 Exfiltrated 596GB 420 Proof 6d 02:09 About company: NTN Bearing is a producer of ball and roller bearings, with plants around the globe and a strong, domestic manufacturing network. Data description: Confidential, Employees' PII (Personally Identifiable Information), Correspondence, Financial, Engineering, Contracts, Agreements, NDA, FULL INFO SunSource 2026-04-20 sun-source.com USA $2B 3500 Exfiltrated 700GB 3401 Disclosed About company: SunSource is a distribution company, providing products, services, and information in…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

