Ransomware victim disclosure
← All victimsQualiflex Solutions AG
listed as Qualiflex Solutions | qualiflex.solutions · Claimed by Payload · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Payload
- Status
- Data leaked
- Sector
- Business Services
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileQualiflex Solutions AG specializes in automation and control technology, providing building automation, industrial automation, IT infrastructure, and managed services to business clients. The company has completed projects for notable clients including Vita Bad AG, Coop, and Stadttheater Bern.
- Industry
- Automation & Control Technology; IT Infrastructure & Managed Services
Attack summary
Severity: medium — Confirmed data publication by ransomware operator with access to business and client records; no specific regulated data types confirmed, but IT services company likely holds moderate sensitivity data.The ransomware group Payload claims to have compromised Qualiflex Solutions AG and published data from the breach. Specific details about the scope of exfiltration or encryption are not stated in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business/project documentation
- client information
- IT infrastructure records
What the group claims
Qualiflex Solutions AG specializes in automation and control technology, offering services in building automation, industrial automation, IT infrastructure, and managed services. Their intended clients include businesses seeking IT solutions, infrastructure renewal, and automation systems for various applications. The company has successfully completed projects for clients such as Vita Bad AG, Coop, and Stadttheater Bern. With a team of skilled professionals, Qualiflex Solutions AG aims to enhance operational efficiency and technological integration for their clients.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

