LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › dgr.at Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

dgr.at Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 4, 2025
dgr.at Listed by qilin Ransomware Group

Reported April 4, 2025.

HIGH
Severity
April 4, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Austrian domain dgr.at was listed on 4 April 2025 by the Qilin ransomware group, which claims to have exfiltrated internal files. Individuals connected to the organisation should check for any official notices and change relevant passwords or monitor their accounts.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 4 April 2025 a ransomware group known as qilin publicly listed the Austrian firm dgr.at on its leak site, claiming it had stolen internal company files and would release them for download ten days later. For anyone whose personal or business details sit inside those systems—employees, customers, or partner firms in the building-services trade—the practical question is straightforward: what information may now be outside the organisation’s control, and what can be done about it.

Public detail remains limited. The number of people affected is unknown, and the exact contents of the files have not been independently confirmed. What is known is that a ransomware group has asserted control over internal data belonging to a company that supplies specialised software to tradespeople across Austria and beyond. That claim alone is enough to warrant careful attention.

Breaking down the breach

According to the listing published on 4 April 2025, qilin states that it has exfiltrated internal files from dgr.at in the course of a ransomware attack. The group further claims that “all data of this company will be available for download on 14.04.2025.” No independent verification of the intrusion, the volume of data taken, or the technical method used has been made public. The number of individuals whose information may be involved is listed as unknown. Beyond the group’s own statement, therefore, the scale, timing of the original compromise, and precise attack vector remain undisclosed.

Who is qilin?

Qilin is a well-documented ransomware operation that has been active for several years. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. Victims are routinely named on a dedicated leak site, often with sample files or countdown timers. Public reporting has linked qilin to attacks across multiple sectors and countries; the group is known for targeting mid-sized organisations whose operational data carries commercial or personal value. Its listing of dgr.at should be treated as an unverified claim by the actors themselves rather than as confirmed fact.

Who is dgr.at?

dgr.at develops and supplies the ERP software suite PROFI.neo, marketed to companies in the building-services sector—electrical contractors, plumbers, heating, ventilation and air-conditioning installers, and related trades. Organisations of this type routinely hold customer contact details, project records, invoices, employee information and technical documentation. Because the software sits at the centre of day-to-day operations for many small and medium-sized firms, a compromise of the vendor’s own systems can have knock-on effects for the businesses that rely on it. The company’s Austrian domain and focus on the DACH region place it within a network of regional trade suppliers whose data often includes both commercial and personal identifiers.

What data was at risk

The only description provided by the listing is “internal files exfiltrated in ransomware attack.” No further breakdown—customer lists, employee records, source code, financial documents or otherwise—has been published or independently verified. Organisations that produce ERP software for the trades typically store customer account data, project histories, billing information, employee records and technical configuration files. Whether any of those categories were among the files claimed by qilin remains unconfirmed. Readers should therefore treat the precise contents as unknown until more reliable information appears.

The real-world impact

If the group’s claim is accurate, the immediate risk is unauthorised access to whatever internal material was taken. For individuals this can mean exposure of contact details, employment information or project-related personal data, which in turn can enable phishing, identity misuse or targeted social engineering. For partner firms that use PROFI.neo, the concern is that commercial or operational data shared with dgr.at may now sit outside controlled systems. The organisation itself faces the usual consequences of a ransomware incident: potential disruption, reputational damage, regulatory notification duties under European data-protection rules, and the cost of investigation and remediation. Because the number of people affected is unknown and the data types remain unspecified, the full extent of harm cannot yet be measured.

If your data was in this claimed breach

Anyone who has dealt with dgr.at—as an employee, customer or business partner—should treat the possibility of exposure seriously even while details stay limited. Change passwords on any accounts that may have been linked to the company, enable multi-factor authentication wherever it is offered, and watch for unexpected messages that reference building-services projects or invoices. Monitor financial and credit activity for unusual behaviour. Free tools exist that allow you to check whether your email address has already appeared in known breach datasets; running such a scan can give an early indication of whether your information has surfaced elsewhere. If you believe sensitive personal data has been compromised, consider placing fraud alerts with relevant credit agencies and retaining records of any suspicious contact for later reporting to local authorities or data-protection regulators.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companydgr.at security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See dgr.at’s full breach history →

More recent breaches

Luminex Software Listed by qilin Ransomware GroupDecember 31, 2025Z-Tronix Listed by qilin Ransomware GroupDecember 31, 2025Questica Listed by qilin Ransomware GroupDecember 28, 2025LogicVein Listed by qilin Ransomware GroupDecember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the dgr.at Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram