Ransomware victim disclosure
← All victimsmende-grundbesitz.de
Claimed by Safepay · listed 9 days ago
Status timeline
- ListedJul 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Germany
- Sector
- Business Services
- Listed on leak site
- Jul 20, 2026
About the victim
AI dossier — public-source company profileMende Grundbesitzverwaltungs GmbH is a Berlin-based property management company founded in 1990, specializing in residential, commercial, and mixed-use real estate administration. The company manages over 1,000 residential and commercial units across Berlin, providing services including tenant management, shared property administration, operating cost accounting, and tenant dispute resolution.
- Industry
- Real Estate Management & Administration
- Address
- Berlin, Germany
- Founded
- 1990
Attack summary
Severity: high — Confirmed data exfiltration from a property management firm handling sensitive tenant information, financial records, and property details across 1,000+ units; likely includes PII of tenants and clients at scale.The SafePay group claims to have attacked Mende Grundbesitz and has published data from the breach. The group's post references the company's founding and business operations, indicating exfiltration of company information.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational records
- Property management files
- Tenant/client information
- Financial records
- Business correspondence
What the group claims
Founded in 1994, the company specializes in the professional administration of residential, commercial, and mixed-use real estate throughout the Berlin …
Sources
Source
Indexed 9 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

