Ransomware victim disclosure
← All victimsJäcklin GmbH
listed as jaecklin-industrial.de · Claimed by Safepay · listed 9 days ago
Status timeline
- ListedJul 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Jul 20, 2026
About the victim
AI dossier — public-source company profileJäcklin GmbH is a German family-owned manufacturer founded in 1935, specializing in screw compressors (airends) for rail applications and rotor manufacturing for compressors and pumps. Based in Augsburg with approximately 80 employees, the company is a global leader in high-precision, custom pneumatic components for train brake systems and related rail infrastructure.
- Industry
- Industrial Machinery & Precision Engineering — Screw Compressors & Rotors
- Address
- Unterer Talweg 50, 86179 Augsburg, Germany
- Employees
- 80
- Founded
- 1935
Attack summary
Severity: medium — Data has been published (disclosed_status confirms 'data_published'), indicating confirmed exfiltration. However, no proof file count is advertised in the post excerpt, and the data appears to be internal business/technical files rather than regulated personal or financial data at scale. The company is small (80 employees) and operational impact to rail systems is not explicitly claimed.The SafePay group claims to have compromised Jäcklin GmbH and published exfiltrated data. The specific nature of data accessed and whether encryption occurred is not detailed in the truncated leak post provided.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- technical documentation
- customer data
- operational files
What the group claims
Founded in 1935 by Julius Jäcklin, the company has developed from a regional machine repair workshop into a globally recognized …
Sources
Source
Indexed 9 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

