EDER Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The EDER Listed by rhysida Ransomware Group (reported June 18, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In June 2023, the Austrian construction-materials group EDER appeared on a leak site operated by the ransomware group rhysida. The listing asserted that internal files had been taken in a ransomware attack and then placed in public reach. How many people are affected remains unknown, and the precise contents of the material have not been independently confirmed. For employees, contractors, customers and partners whose details may sit inside those files, the practical question is straightforward: what might now be circulating, and what steps reduce the resulting risk.
Public detail is limited to the group’s own claim and a brief organisational description. That is enough to warrant attention, because construction firms routinely hold operational, commercial and personal records that can be misused long after an incident is first reported.
What happened
On or around 18 June 2023, EDER was listed by the rhysida ransomware group. According to the listing, internal files were exfiltrated during a ransomware attack. The group further claimed that “all files was uploaded to public access” and invited “data hunters” to make use of them, stating the documents were at “100%.” No independent confirmation of the intrusion method, the exact date of compromise, the volume of data, or the number of people affected has been supplied in the available record. The scale of any encryption or operational disruption inside EDER is likewise undisclosed.
What is known is therefore narrow: a public claim of exfiltration and subsequent release of internal material belonging to the EDER group of companies. Everything beyond that claim remains unconfirmed.
The group behind it: rhysida
Rhysida is a ransomware operation that became publicly visible in 2023. Like many contemporary groups, it has followed a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group has typically operated a leak site on which it names victims, posts samples or full archives, and sets deadlines. It has been observed targeting organisations across multiple sectors and geographies rather than a single industry niche.
Rhysida has been associated with ransomware-as-a-service style activity, in which affiliates may conduct intrusions and share proceeds with the operators who supply the malware and infrastructure. Public reporting has linked the name to a series of listings of companies, public bodies and other entities; each listing is a claim by the group until verified by the victim or by independent analysis. In the present case, the only specific assertion about EDER is the one appearing on the leak site itself—that internal files were taken and made publicly available. No further statements by rhysida about this victim are recorded in the facts at hand.
EDER and its sector
EDER is described as a group of companies centred on building materials and related construction products in Upper Austria. Its operations include brick plants in Peuerbach and Weibern, four ready-mixed concrete plants, Systembau Eder (which supplies prefabricated stairs, constructive concrete components and double-wall systems for industrial building construction), and its own vehicle fleet. In short, it is a mid-sized industrial supplier serving the construction sector.
Firms of this type sit at the intersection of manufacturing, logistics and project delivery. They commonly maintain records of employees and contractors, customer and supplier contracts, production and quality data, vehicle and site logistics, and financial and commercial correspondence. A breach at such an organisation is consequential because the data can affect both the company’s competitive position and the privacy and security of the individuals whose details appear in personnel, billing or project files. Construction-supply chains also involve many smaller partners; exposure of shared documents can ripple beyond the primary victim.
The information in question
The available record states only that “internal files” were exfiltrated in a ransomware attack and that the group claimed the documents had been uploaded for public access. No inventory of file types, no count of records, and no confirmation of personal-data categories have been published in the facts provided. It is therefore not possible to state as fact which specific fields—names, contact details, identity documents, payroll data, contracts or otherwise—were included.
Organisations in EDER’s position typically hold human-resources files, customer and supplier databases, technical drawings or specifications, invoices, and operational logs. Whether any or all of those categories were present in the material rhysida claims to have released remains unconfirmed. Readers should treat any assertion about exact contents as unverified until corroborated by the company or by reliable forensic reporting.
What's at stake
When internal corporate files are published, the risks are concrete even if the precise data set is unknown. Individuals whose information appears in those files may face phishing or social-engineering attempts that exploit accurate personal or employment details. Business partners may see commercial terms, pricing or project information used by competitors or fraudsters. The organisation itself may confront regulatory notification duties, contractual disputes and lasting damage to trust.
Because the number of people affected is unknown and the file list is undisclosed, the prudent assumption for anyone connected to EDER—staff, former staff, contractors, customers or suppliers—is that relevant records could be among the material the group claims to have released. The following points summarise the main practical concerns:
- Possible misuse of personal or contact details for targeted fraud or identity-related scams.
- Exposure of employment, payroll or contractor information that could enable further social engineering.
- Leakage of commercial contracts, pricing or project data that harms business relationships.
- Uncertainty about scope, which makes it harder for individuals to know whether they are directly affected.
- Ongoing availability of any published archive, which can be copied and re-shared long after the initial listing.
What to do if you're exposed
If you have a past or present connection to EDER, treat the incident as a prompt to tighten basic defences rather than as proof that your own data is confirmed stolen. Change passwords on accounts that reused credentials linked to work email, enable multi-factor authentication wherever it is offered, and watch for unexpected messages that reference the company, invoices or personal details. Monitor financial and credit activity for unfamiliar applications or accounts. If you receive extortion or phishing contact that cites the breach, do not pay or engage; report it to the relevant authorities and to your organisation’s security or HR contact if appropriate.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check will not confirm or deny inclusion in this specific incident, but it can show whether the same address has surfaced elsewhere and help you prioritise further password and account hygiene.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Western National Group Listed by rhysida Ransomware GroupZiegelwerk Eder Listed by rhysida Ransomware GroupLawson Roofing Listed by rhysida Ransomware GroupCator Ruma & Associates Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the EDER Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.