LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › derichsukonertz.de Listed by lynx Ransomware Group

HIGH severityUnverified claimHow we verify

derichsukonertz.de Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 19, 2025
derichsukonertz.de Listed by lynx Ransomware Group

Reported February 19, 2025.

HIGH
Severity
February 19, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

derichsukonertz.de has been listed by the lynx Ransomware Group, which states that internal files were exfiltrated in a ransomware attack. The incident was disclosed on February 19, 2025, with the number of people affected remaining undisclosed; anyone connected to the organisation should review their exposure and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For employees, suppliers and business partners of a long-established German industrial manufacturer, the appearance of a company name on a ransomware leak site raises immediate practical questions: whether internal documents, correspondence or commercial records have left the organisation’s control, and what that could mean for privacy, contracts and day-to-day operations. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone whose information may have been held by the firm.

On 19 February 2025 the domain derichsukonertz.de was reported as listed by the ransomware group known as lynx. The group claims that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and no further confirmed inventory of the material has been published. What follows summarises only what is on record and places it in the context of the organisation and the actor involved.

What happened

According to the available report, derichsukonertz.de was listed by the lynx ransomware group on 19 February 2025. The listing asserts that internal files were taken during a ransomware incident. No public confirmation of the attack’s technical method, the precise date of intrusion, the volume of data removed, or any ransom demand has been released. The number of individuals whose information may be involved is listed as unknown. In short, the sole concrete claim is that the organisation appears on the group’s leak site in connection with the exfiltration of internal files; everything else remains undisclosed.

The group behind it: lynx

Lynx is a ransomware operation that became publicly visible in 2024 and functions as a ransomware-as-a-service model. Like many contemporary groups, it typically combines encryption of victim systems with the theft of data, then threatens to publish the material on a dedicated leak site if payment is not made. The group has been observed targeting organisations across multiple sectors and geographies, posting victim names and, in some cases, sample files to increase pressure. Its listings are claims made by the actors themselves; they are not independent verification that every asserted detail is accurate. In this instance the only statement attributed to lynx is that derichsukonertz.de suffered a ransomware attack in which internal files were allegedly exfiltrated. No additional claims specific to this victim have been placed on the public record.

Who is derichsukonertz.de?

Derichsukonertz.de is the online presence of F. J. Derichs, a German manufacturer of industrial gears that has operated since 1967. The company produces a range of gear components—from small measuring pinions to heavy-duty drive systems—supplied fully finished to drawing or sample, or as partial machining and retrofit work, for customers across industrial sectors. Firms of this type routinely hold engineering drawings, production records, customer and supplier contact details, commercial contracts, quality documentation and internal administrative files. Because such data underpins both manufacturing operations and ongoing business relationships, any unauthorised removal of internal files carries consequences that extend beyond the company itself to its partners and staff.

What was likely exposed

The only data type named in the report is “internal files exfiltrated in a ransomware attack.” No further breakdown—such as whether the material included personal data of employees, customer lists, financial records or technical drawings—has been disclosed. Organisations engaged in precision industrial manufacturing typically store engineering specifications, order histories, correspondence, personnel information and commercial agreements. It is therefore possible that some combination of these categories was among the files taken, yet the exact contents remain unconfirmed. Readers should treat any more specific description as speculative until an official inventory is released.

The real-world impact

For individuals whose details may appear in the exfiltrated material, the principal risks are misuse of contact or identity information, targeted phishing that references genuine business relationships, and potential exposure of employment or contractual data. For the organisation the consequences can include disruption of production planning, loss of competitive technical information, strain on customer and supplier trust, and the operational cost of investigation and recovery. Because the scale of the incident and the precise nature of the files are unknown, the severity of these effects cannot yet be quantified; the prudent stance is to assume that any internal document held by the company could have been copied and to act accordingly.

What to do if you're exposed

If you have reason to believe your information was held by derichsukonertz.de, begin by monitoring financial and email accounts for unusual activity and treat unexpected messages that reference the company with caution. Change passwords on any accounts that may have shared credentials with work systems, and enable multi-factor authentication where available. Consider placing fraud alerts with relevant credit agencies if personal identifiers could be involved. Finally, you can run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; doing so provides an early indication of whether your details have circulated more widely.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyderichsukonertz.de security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See derichsukonertz.de’s full breach history →

More recent breaches

saacke.com Listed by lynx Ransomware GroupSeptember 30, 2025Schmiedetechnik Plettenberg GmbH & Co KG Listed by lynx Ransomware GroupMarch 5, 2025Stürmer Maschinen Listed by lynx Ransomware GroupFebruary 8, 2025www.kurita.eu Listed by lynx Ransomware GroupMay 10, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the derichsukonertz.de Listed by lynx Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lynx — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram