dgr.at Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Austrian domain dgr.at was listed on 4 April 2025 by the Qilin ransomware group, which claims to have exfiltrated internal files. Individuals connected to the organisation should check for any official notices and change relevant passwords or monitor their accounts.
On 4 April 2025 a ransomware group known as qilin publicly listed the Austrian firm dgr.at on its leak site, claiming it had stolen internal company files and would release them for download ten days later. For anyone whose personal or business details sit inside those systems—employees, customers, or partner firms in the building-services trade—the practical question is straightforward: what information may now be outside the organisation’s control, and what can be done about it.
Public detail remains limited. The number of people affected is unknown, and the exact contents of the files have not been independently confirmed. What is known is that a ransomware group has asserted control over internal data belonging to a company that supplies specialised software to tradespeople across Austria and beyond. That claim alone is enough to warrant careful attention.
Breaking down the breach
According to the listing published on 4 April 2025, qilin states that it has exfiltrated internal files from dgr.at in the course of a ransomware attack. The group further claims that “all data of this company will be available for download on 14.04.2025.” No independent verification of the intrusion, the volume of data taken, or the technical method used has been made public. The number of individuals whose information may be involved is listed as unknown. Beyond the group’s own statement, therefore, the scale, timing of the original compromise, and precise attack vector remain undisclosed.
Who is qilin?
Qilin is a well-documented ransomware operation that has been active for several years. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. Victims are routinely named on a dedicated leak site, often with sample files or countdown timers. Public reporting has linked qilin to attacks across multiple sectors and countries; the group is known for targeting mid-sized organisations whose operational data carries commercial or personal value. Its listing of dgr.at should be treated as an unverified claim by the actors themselves rather than as confirmed fact.
Who is dgr.at?
dgr.at develops and supplies the ERP software suite PROFI.neo, marketed to companies in the building-services sector—electrical contractors, plumbers, heating, ventilation and air-conditioning installers, and related trades. Organisations of this type routinely hold customer contact details, project records, invoices, employee information and technical documentation. Because the software sits at the centre of day-to-day operations for many small and medium-sized firms, a compromise of the vendor’s own systems can have knock-on effects for the businesses that rely on it. The company’s Austrian domain and focus on the DACH region place it within a network of regional trade suppliers whose data often includes both commercial and personal identifiers.
What data was at risk
The only description provided by the listing is “internal files exfiltrated in ransomware attack.” No further breakdown—customer lists, employee records, source code, financial documents or otherwise—has been published or independently verified. Organisations that produce ERP software for the trades typically store customer account data, project histories, billing information, employee records and technical configuration files. Whether any of those categories were among the files claimed by qilin remains unconfirmed. Readers should therefore treat the precise contents as unknown until more reliable information appears.
The real-world impact
If the group’s claim is accurate, the immediate risk is unauthorised access to whatever internal material was taken. For individuals this can mean exposure of contact details, employment information or project-related personal data, which in turn can enable phishing, identity misuse or targeted social engineering. For partner firms that use PROFI.neo, the concern is that commercial or operational data shared with dgr.at may now sit outside controlled systems. The organisation itself faces the usual consequences of a ransomware incident: potential disruption, reputational damage, regulatory notification duties under European data-protection rules, and the cost of investigation and remediation. Because the number of people affected is unknown and the data types remain unspecified, the full extent of harm cannot yet be measured.
If your data was in this claimed breach
Anyone who has dealt with dgr.at—as an employee, customer or business partner—should treat the possibility of exposure seriously even while details stay limited. Change passwords on any accounts that may have been linked to the company, enable multi-factor authentication wherever it is offered, and watch for unexpected messages that reference building-services projects or invoices. Monitor financial and credit activity for unusual behaviour. Free tools exist that allow you to check whether your email address has already appeared in known breach datasets; running such a scan can give an early indication of whether your information has surfaced elsewhere. If you believe sensitive personal data has been compromised, consider placing fraud alerts with relevant credit agencies and retaining records of any suspicious contact for later reporting to local authorities or data-protection regulators.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Luminex Software Listed by qilin Ransomware GroupZ-Tronix Listed by qilin Ransomware GroupQuestica Listed by qilin Ransomware GroupLogicVein Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the dgr.at Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.