Ransomware victim disclosure
← All victimsKarl Geuther & Co.
listed as Karl Geuther · Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 4, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileKarl Geuther & Co. is a German company operating across five business areas: shipping, stevedoring/port handling, transport logistics and freight forwarding, mail order, and tourism. The company appears to be a diversified logistics and trade services group based in Germany. No further details on scale or founding date are available from the leak post or a public site.
- Industry
- Shipping, Stevedoring & Logistics
Attack summary
Severity: critical — The threat actor claims exfiltration of 45 GB of data containing regulated personal identity documents (passports, birth certificates, driving licences) constituting PII at scale, alongside financial records and contracts — meeting the threshold for critical under GDPR-sensitive personal data exposure.Akira claims to have exfiltrated approximately 45 GB of corporate data from Karl Geuther & Co., including employee identity documents (IDs, passports, driving licences, birth certificates), financial records, and contracts, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee identity documents (IDs, passports, driving licences, birth certificates)
- Financial records
- Contracts
What the group claims
Karl Geuther & Co. operates in five business areas: shipping, ste vedoring/port handling, transport logistics/freight forwarding, m ail order, and tourism. We will upload 45gb of corporate data soon. Employee documents (I Ds, passports, DLs, birth certs), financials, contracts and so on .
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

