Ransomware victim disclosure
← All victimsKFZ Sauter GmbH Co. KG
Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Germany
- Listed on leak site
- Feb 18, 2026
About the victim
AI dossier — public-source company profileKFZ Sauter GmbH & Co. KG is a German automotive services company located in Bubesheim, Bavaria. It provides used and accident vehicle buying/selling, multi-brand repair services with a large used-parts shop, and end-of-life vehicle recycling in compliance with environmental regulations. The business operates as a full-service vehicle lifecycle provider for private and commercial customers.
- Industry
- Automotive Repair & Used Vehicle Trading
- Address
- Industriestraße 15–17, 89347 Bubesheim, Germany
Attack summary
Severity: high — Confirmed exfiltration and publication of GDPR-regulated personal data alongside financial, accounting, and legal documents constitutes significant sensitive data exposure, triggering EU data protection obligations and material business harm.The Nightspire ransomware group claims to have exfiltrated data from KFZ Sauter GmbH & Co. KG, with the disclosed data categories including banking/finance records, accounting documents, contracts, legal files, GDPR-regulated personal data, and general documents and images. The disclosure status is listed as data_published, indicating the data has already been released.
Data the group says was taken
AI dossier — extracted from the leak post- Banking and finance records
- Accounting documents (Buchhaltung)
- Contracts and legal files
- GDPR personal data
- Documents and images
What the group claims
- Banking Finance- Accounting Buchhaltung- Contracts Legal- GDPR Personal Data- Documents Images
Sources
- Victim sitekfz-sauter.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

