Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationoperational-disruptionunderground-data-leakfinancial-sector-threat

Ransomware and Cyberattacks Hit German Firms, Including Alleged DragonForce Data Theft

Updated 3mo agoFirst seen Feb 5, 20263 sources

A series of cyber incidents affected German organizations, including an alleged DragonForce ransomware data theft from insurer HanseMerkur. DragonForce claimed to have stolen nearly 97 GB of internal corporate data and leaked materials described as including financial documents (e.g., invoices, tax notes, vouchers) and documents referencing HanseMerkur’s UAE partner Emirates Insurance; HanseMerkur had not publicly confirmed the claim at the time of reporting. Reporting also noted DragonForce’s broader activity and claimed partnerships in the ransomware ecosystem.

Separately, the Buhlmann Group was named by the Akira ransomware group, which claimed theft of 55 GB of sensitive data and threatened publication; Buhlmann indicated a US subsidiary was impacted and stated German/EU entities and their systems were not affected. In another incident, beverage bottler Romina Mineralbrunnen reported a cyberattack that left it unreachable by phone/email and caused a production stoppage; authorities were reported to be investigating, with no confirmed details yet on initial access, malware type, or data theft.

Share:
Ransomware and Cyberattacks Hit German Firms, Including Alleged DragonForce Data Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 5, 20265mo ago

DragonForce claims breach of HanseMerkur and data leak

Reports said the DragonForce ransomware gang allegedly stole and leaked nearly 97 GB of internal corporate data from German insurer HanseMerkur, including financial documents and files referencing partner Emirates Insurance. HanseMerkur had not publicly acknowledged the claim at the time of reporting.

Buhlmann says only U.S. subsidiary systems were affected

A Buhlmann Group spokesperson said the impacted IT system was used only in the United States and that the German headquarters and other group entities, especially in Germany and the EU, were not affected. The company said no data outside the U.S. location was at risk.

Akira claims ransomware attack on Buhlmann Group

The Akira ransomware group posted on the darknet that it had stolen sensitive information from the Buhlmann Group and threatened to publish 55 GB of allegedly exfiltrated data. The claim indicated a ransomware incident affecting the steel trader.

Feb 4, 20265mo ago

Police begin investigating attack on Romina Mineralbrunnen

Police in Reutlingen were reported to be investigating the cyberattack against Romina Mineralbrunnen. The investigation was disclosed in media reporting after the company's production outage became public.

Romina Mineralbrunnen hit by cyberattack, production halted

Beverage bottler Romina Mineralbrunnen GmbH in Reutlingen-Rommelsbach was struck by a cyberattack that brought its production facilities to a standstill. The company said it was unreachable by phone and email following the incident, while it remained unclear whether any data had been stolen.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
4 linked
Organizations
14 linked
CybernewsGroup-IBCricket WirelessMarks & SpencerBelkHanseMerkurEmirates InsuranceMobilelinkCo-opSüdwest PresseRomina Mineralbrunnen GmbHReutlinger General-Anzeigerbuten un binnenBuhlmann Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ransomware and Cyberattacks Hit German Firms, Including Alleged DragonForce Data Theft | Mallory