Ransomware victim disclosure
← All victimsPlanungsgruppe M+M AG
Claimed by AUR0RA · listed 4 hours ago
Status timeline
- ListedAug 20, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profilePlanungsgruppe M+M AG is a German architecture and engineering firm headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices. The firm provides architecture, urban planning, structural engineering, building physics, fire protection, BIM, landscape planning, and interior design services, with over 5,200 completed projects spanning decades.
- Industry
- Architecture, Urban Planning & Structural Engineering
- Address
- Böblingen, Baden-Württemberg, Germany (headquarters); 10 offices in Böblingen, Stuttgart, München, Nürnberg, Regensburg, Ingolstadt, Augsburg, Esslingen, Mannheim, Frankfurt
- Employees
- 432
Attack summary
Severity: critical — Exfiltration of 268 GB confirmed with complete financial systems (banking, accounting, payroll), employee personal data (289 staff directories, HR records), and banking credentials/software databases. Sensitive PII at scale combined with financial infrastructure compromise.AUR0RA claims to have exfiltrated two complete file servers (MMBB04, MMBB05) plus financial, banking, document management, email, and payroll systems. The dataset spans 268 GB of approximately 124,000 files covering 2006–2026, including employee directories, financial records, banking credentials, and HR data.
Data the group says was taken
AI dossier — extracted from the leak post- Employee home directories (289 staff)
- DATEV financial/accounting archives
- SFirm banking software databases
- ELO document management system exports
- Outlook email archives (PSTs)
- Payroll and HR records
- Project documentation
- Banking credentials and configurations
What the group claims
German Aktiengesellschaft headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices. Annual revenue approximately €52 million. Provides architecture, urban planning, structural engineering, building physics, fire protection, BIM, landscape planning, and interior design services.
The leak post
captured from the group's site[ Primed Halberstadt Medizintechnik GmbH — a German manufacturer of medical devices founded in 1946 and now part of the PE-backed PP Medtech group (Wiesmann & Co. KG). The exfiltration captured four entire server volumes: Daten (883 GB) — File server: 289 employee home directories (547 GB), Czech subsidiary data (66 GB), production processes (162 GB), machine configurations (81 GB) EE (807 GB) — Enterprise system: Apollo ERP, VBANK banking (8 accounts), complete database backup (100.6 GB, dated June 3), product images WINDVSW1 (344 GB) — Windows server: DATEV accounting (115+ data directories including LODAS payroll), bank transfers, DMS exports dmsscan (12 GB) — Scanned documents from 51+ employee DMS mailboxes A database backup (spiel.zip.001–010, 100.6 GB) was created on 2026-06-03 ](http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/primed-halberstadt-medizintechnik-b278bad0)[ Planungsgruppe M+M AG is a German Aktiengesellschaft headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices (Böblingen, Stuttgart, München, Nürnberg, Regensburg, Ingolstadt, Augsburg, Esslingen, Mannheim, Frankfurt). Annual revenue: approx…
Data the group says was taken
- file server data
- DATEV financial archives
- SFirm banking software databases
- ELO document management system
- Outlook email archives (PST)
- payroll/HR data
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

