LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ascom Holding AG Listed by hellcat Ransomware Group

HIGH severityUnverified claimHow we verify

Ascom Holding AG Listed by hellcat Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 16, 2025
Ascom Holding AG Listed by hellcat Ransomware Group

Reported March 16, 2025.

HIGH
Severity
March 16, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ascom Holding AG appeared on a data-leak site operated by the hellcat ransomware group on 16 March 2025, after the attackers published internal files stolen during a ransomware incident. Individuals whose information may have been among the exfiltrated records should review any notices from the company and consider protective steps such as monitoring accounts and changing passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a company that supplies communication systems to hospitals and other critical workplaces appears on a ransomware group's leak site, the immediate concern is not abstract cybersecurity theory but the practical risk that internal records, contracts, and technical materials could be misused. On 16 March 2025, Ascom Holding AG was listed by the group known as hellcat, which claimed to have stolen 44 GB of sensitive data. The number of people whose personal information may be involved remains unknown, yet anyone who has dealt with Ascom—employees, partners, or customers—has reason to understand what is publicly reported and what remains unconfirmed.

Public detail is limited to the group's claim and the reported contents of the haul. No independent confirmation of the full scope or of any subsequent data release has been provided in the available facts. Still, the listing itself is enough to warrant careful attention from those who may be affected.

Breaking down the breach

According to the reported summary, hellcat claimed to have exfiltrated 44 GB of internal files from Ascom Holding AG in a ransomware attack. The materials named include internal reports, sales documents, confidential contracts, development tools, and source code. The incident was reported on 16 March 2025. Beyond that date and the stated volume and categories, public information does not disclose how the attackers gained access, whether systems were encrypted, how long the intrusion lasted, or whether any ransom demand was issued or paid. The number of individuals whose data may have been present is listed as unknown. The listing on the group's site constitutes a claim by hellcat; it has not been independently verified in the facts provided.

The group behind it: hellcat

Hellcat is a ransomware operation that has appeared in public reporting as a group that encrypts systems and threatens to publish stolen data on dedicated leak sites if its demands are not met. Like many such actors, it typically advertises victims by name, volume of data taken, and sample file types in order to pressure organisations. Prior activity attributed to hellcat in open sources has followed this pattern of double-extortion: data theft followed by a public listing. In the present case the group claims to have taken 44 GB of Ascom material and to have listed the company. No further statements by hellcat about this specific victim—such as deadlines, sample screenshots, or confirmation of a full dump—are contained in the available facts, so those details remain unconfirmed.

Who is Ascom Holding AG?

Ascom Holding AG is a Swiss technology company that develops and supplies information and communication systems, particularly wireless nurse-call, messaging, and workflow solutions used in healthcare facilities and other professional environments. Organisations of this type routinely hold engineering documentation, customer contracts, sales records, and proprietary source code. Because Ascom products sit inside hospitals and similar settings, a breach of its internal systems can raise secondary concerns about the integrity of support processes or the exposure of commercial relationships. The company itself has not been described in the facts as having confirmed or denied the listing; the public record rests on the ransomware group's claim.

What data was at risk

The facts state that the exfiltrated material consisted of internal files: internal reports, sales documents, confidential contracts, development tools, and source code, amounting to 44 GB. No further breakdown—such as whether employee personal data, customer contact lists, or patient-related information was present—is provided. For a company of Ascom's profile, typical holdings would include commercial agreements, technical designs, and internal correspondence. Because the exact contents beyond the named categories remain unconfirmed, it is not possible to state with certainty which individuals or third parties are affected. The reported summary simply characterises the haul as sensitive internal data stolen in a ransomware attack.

Why it matters

For people whose information may sit inside those files, the concrete risks include targeted phishing that references genuine contracts or project names, competitive misuse of sales or pricing data, and potential reverse-engineering of proprietary tools or code. Employees or contractors could face identity-related fraud if personal details were embedded in the documents. For Ascom the consequences include possible disruption of commercial relationships, the cost of forensic investigation and remediation, and reputational pressure from partners who rely on the confidentiality of shared materials. Because the number of affected individuals is unknown and the full data set has not been independently described, the precise scale of harm cannot yet be measured; the listing alone, however, creates a window of elevated risk until more is known.

If your data was in this claimed breach

If you have worked with, supplied, or been employed by Ascom Holding AG, treat the possibility of exposure seriously even while details remain limited. Change passwords on any accounts that may have been linked to Ascom systems, enable multi-factor authentication where available, and watch for unsolicited messages that cite internal project names or contract details. Monitor financial and credit activity for unusual behaviour. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Until Ascom or independent investigators provide further confirmation, these basic steps remain the most practical response available to ordinary people who may be affected.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAscom Holding AG security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Ascom Holding AG’s full breach history →

More recent breaches

CVTE Listed by hellcat Ransomware GroupApril 7, 2025Racami Listed by hellcat Ransomware GroupApril 5, 2025Asseco Listed by hellcat Ransomware GroupApril 5, 2025Transsion Listed by AiLock Ransomware GroupMarch 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ascom Holding AG Listed by hellcat Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by hellcat — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram