Ransomware victim disclosure
← All victimsHLF Heizung-Sanitär GmbH
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Germany
- Sector
- Construction
- Listed on leak site
- Mar 25, 2026
About the victim
AI dossier — public-source company profileHLF Heizung-Sanitär GmbH is a regional building services company based in Goslar, Germany, serving the areas of Goslar, Vienenburg, Liebenburg, and Bad Harzburg. The company provides heating systems, bathroom installation and renovation, climate control, and ventilation services to both private and commercial customers. With over 100 skilled employees, the company offers planning, installation, maintenance, and subsidy advisory services.
- Industry
- Heating, Sanitation & Building Services Engineering
- Address
- Goslar, Lower Saxony, Germany
- Employees
- 100+
Attack summary
Severity: medium — Data has been marked as published, indicating likely exfiltration, but no leak post content is available to confirm the type, volume, or sensitivity of data involved. The company is a mid-sized regional trade services firm, reducing the likelihood of large-scale regulated data exposure, but the published status elevates severity above low.The Nightspire ransomware group claims to have attacked HLF Heizung-Sanitär GmbH and has published data (disclosed status: data_published), though the specific leak post content is not currently available. The nature and volume of exfiltrated data cannot be confirmed from the available post.
What the group claims
Data is not available now.
Sources
- Victim sitewww.hlf-goslar.de
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

