Ransomware victim disclosure
← All victimsComing soon
Claimed by Rhysida · listed 4 hours ago
Status timeline
- ListedAug 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Rhysida
- Status
- Data leaked
- Listed on leak site
- Aug 21, 2026
About the victim
AI dossier — public-source company profileUnknown government or public sector entity. The leak post references inquiries from the House of Representatives, GWT oversight documents, and KRITIS (Critical Infrastructure) classifications, indicating a German government agency or public institution.
- Industry
- Government / Public Administration
Attack summary
Severity: critical — Exfiltration of 5.79 TB from a government entity with confirmed sensitive data: classified documents (GI-Confidential), critical infrastructure plans (KRITIS), personnel files at scale (27k+), financial records, and PII (16k+ emails, 12k names, 148 IBANs). Disclosure of government inquiries and classified material meets critical threshold.Rhysida claims to have exfiltrated 5.79 TB of data from a government or public sector organization. The group states data includes legal proceedings, budget records, contracts, personnel files, classified documents, critical infrastructure information, and contact databases.
Data the group says was taken
AI dossier — extracted from the leak post- Legal/complaints/offenses (77,939 files)
- Financial records/budgets/invoices (55,553 files)
- Contracts and NDAs (46,522 files)
- Personnel files and payroll (27,299 files)
- Government oversight inquiries (13,142 files)
- Classified/confidential documents (11,777 files)
- Critical infrastructure plans (8,110 files)
- Passwords and credentials (5,941 files)
- Health/insurance data (2,738 files)
- Contact databases and phone lists (2,287 files)
- Email addresses (16,389 unique)
- Phone numbers (11,963)
- Personal names (12,076 individuals)
- IBANs (148)
- Financial amounts
What the group claims
Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget, invoices, ProFISKAL, debt collectionContracts 46,522 Contracts, NDAs, procurementHR/Personnel 27,299 Personnel files, payroll, performance reviewsOversight/Government 13,142 Inquiries from the House of Representatives, GWTVConfidential-Secret 11,777 GI-Confidential folders, security classificationInfrastructure/Critical Information Infrastructure 8,110 KRITIS, risk analysis, emergency plansPasswords/secrets 5,941 files containing login credentialsHealth/insurance 2,738 medical benefitsContacts/Addresses 2,287 address databases, phone listsExtracted from the content: 16,389 unique email addresses, 11,963 phone numbers, 12,076 individuals with names, 148 IBANs, 820+ monetary amounts (up to �30 million).And a wealth of other valuable data. More
The leak post
captured from the group's siteTotal capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget, invoices, ProFISKAL, debt collectionContracts 46,522 Contracts, NDAs, procurementHR/Personnel 27,299 Personnel files, payroll, performance reviewsOversight/Government 13,142 Inquiries from the House of Representatives, GWTVConfidential-Secret 11,777 GI-Confidential folders, security classificationInfrastructure/Critical Information Infrastructure 8,110 KRITIS, risk analysis, emergency plansPasswords/secrets 5,941 files containing login credentialsHealth/insurance 2,738 medical benefitsContacts/Addresses 2,287 address databases, phone listsExtracted from the content: 16,389 unique email addresses, 11,963 phone numbers, 12,076 individuals with names, 148 IBANs, 820+ monetary amounts (up to �30 million).And a wealth of other valuable data. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,55…
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

