LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Electro Heat Sweden AB Listed by Rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

Electro Heat Sweden AB Listed by Rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 2, 2026
Electro Heat Sweden AB Listed by Rhysida Ransomware Group

Reported October 2, 2026.

HIGH
Severity
October 2, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Electro Heat Sweden AB was listed today by the Rhysida ransomware group, which claims to have stolen data from the company. Individuals should check whether they may be affected and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure organisations by posting alleged victims on public leak sites, often before any independent confirmation exists. These listings function as extortion leverage: they assert that data was taken and threaten publication, but the claims themselves are not verified incidents until a company, regulator, or other authoritative source speaks.

On 2 October 2026, the group known as Rhysida listed Electro Heat Sweden AB on its leak site. Public detail beyond that listing is limited. Electro Heat Sweden AB has not publicly confirmed the claim as of writing. What follows treats the listing as an unverified claim, explains what such claims typically mean in the current threat landscape, and outlines conditional steps people and partners can take if they believe they may be affected.

What is being claimed

Rhysida has listed Electro Heat Sweden AB on its leak site. According to the listing, the group associates the company with a large volume of material and describes categories it says are included. The reported summary attached to the listing refers to on the order of 1,723,527 files and a data volume stated as 2.55 TB. The same listing text claims the material covers intellectual property such as SolidWorks CAD designs and backups of a PDM drawing vault; accounting and payroll material described as Visma databases and SPCS payroll databases for four legal entities; legally sensitive documents including a confidential settlement agreement said to involve ABB and a payment figure of $75,000, plus dispute correspondence and cost-pricing calculations; and employee personal data said to include passport details and visa-application information such as passport data, address, phone, and date of birth.

The number of people affected is unknown. The method of any intrusion, the timeline of alleged access, and whether any data were actually removed or only described for pressure are not independently established in the material available for this article. Rhysida’s description of file counts, volume, and content is the group’s own claim and marketing on a leak site; it is not a confirmed inventory. Electro Heat Sweden AB has not publicly confirmed the claim as of writing.

Inside Rhysida

Rhysida is a ransomware and extortion actor that has appeared in public reporting since 2023. Like several contemporary groups, it has typically combined encryption of victim systems with theft-and-leak pressure: affiliates seek initial access, move laterally, exfiltrate data, deploy ransomware where it suits their goals, and then use a dedicated leak site to name organisations and threaten release unless payment is made. Public coverage of Rhysida has associated the brand with double-extortion style operations, victim posts that mix company names with alleged sample descriptions, and a model in which affiliates may handle intrusion while the brand provides tooling and publication infrastructure.

Leak-site posts are strategic. They are designed to create urgency for the named organisation, its customers, and its employees. They do not, by themselves, prove that every file category listed was taken, that the volumes are accurate, or that the named company was the original source of every fragment shown. Recycled or exaggerated claims have appeared across the extortion ecosystem. For this Electro Heat Sweden AB listing, only what Rhysida has published as a claim is on the record here; no separate confirmation is included in the facts provided.

Who is Electro Heat Sweden AB?

Electro Heat Sweden AB is presented in the listing context as a firm whose ElectroHeat industrial furnaces are used in manufacturing industries internationally. Organisations in industrial heating and furnace supply typically sit in the manufacturing and capital-equipment supply chain: they design and support specialised equipment, hold engineering drawings and product documentation, manage supplier and customer contracts, and run ordinary corporate functions such as finance, payroll, and HR.

A leak-site listing naming such a company matters because industrial suppliers often hold design IP that competitors or other parties might misuse if it were genuinely exposed, commercial terms that affect negotiations, and workforce data that can enable fraud or identity misuse. Consequence does not require treating Rhysida’s post as proven. The listing alone can create operational distraction, customer questions, and individual concern even while the underlying allegation remains unconfirmed.

What data was at risk

The facts do not establish a verified inventory of exposed data. Data types are not independently confirmed; what exists publicly in this record is Rhysida’s listing language. That language claims intellectual property (including CAD designs and PDM vault backups), accounting and payroll databases across multiple legal entities, legally sensitive commercial documents, and employee personal data including passport- and visa-related fields.

If files of the kinds industrial manufacturers commonly hold were involved in any real incident, organisations in this sector typically retain engineering drawings and product specifications, customer and supplier records, financial systems, payroll and HR files, and sometimes identity documents collected for travel, visas, or compliance. Whether any of that was actually allegedly taken from Electro Heat Sweden AB in this case remains unconfirmed. Readers should treat specific categories and the stated file count and volume as attacker assertions, not as audited findings.

What's at stake

For individuals, the conditional risk is practical rather than theatrical. If employee or contractor personal data—especially passport details, dates of birth, addresses, and phone numbers—were ever exposed, affected people could face targeted phishing, identity fraud, or social-engineering attempts that reference real workplace or travel details. Payroll-related information, if involved, can support tax- or wage-related scams. None of this is established as having occurred for named individuals here; it is the type of harm that follows when such data truly circulate.

For the organisation and its partners, a public extortion listing can strain customer trust, raise questions about drawings and commercial confidentiality, and invite copycat fraud against suppliers and clients who see the company name on a leak site. Legal and contractual sensitivity is also conditional: if settlement or pricing material were genuinely disclosed, counterparties might face negotiation or reputational pressure. Again, Rhysida’s post does not prove that outcome. What a leak-site listing does establish is that a known extortion brand has chosen to name the company and to describe a broad data haul; what it does not establish is confirmation, scope, or fault.

What to do now

If you are an employee, former employee, customer, or partner who thinks your information might appear in material Rhysida claims to hold, proceed on a conditional basis. Watch for unexpected messages that cite the company, furnaces, invoices, payroll, or travel documents; verify any payment or data requests through known official channels; and consider freezing or monitoring credit where local tools exist if passport or identity data could be involved. Prefer unique passwords and multi-factor authentication on email and HR portals so that a single exposed credential is less useful.

Organisations in the supply chain may wish to confirm recent unusual contact about drawings, settlements, or banking changes, and to route concerns through established security or legal contacts rather than through links in unsolicited messages. Because Electro Heat Sweden AB has not publicly stated the incident as of writing, official notices from the company—if any appear—should take precedence over leak-site text.

As a simple personal check, readers can run a free exposure scan of their email address to see whether that address has already appeared in other known breach datasets, and then tighten credentials on any accounts that show up. That step does not prove involvement in this listing; it only helps reduce reuse risk across the wider breach landscape.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyElectro Heat Sweden AB security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Electro Heat Sweden AB’s full breach history →

More recent breaches

Skaff Group Listed by Rhysida Ransomware GroupOctober 3, 2026Mat Bao Corporation Listed by Rhysida Ransomware GroupOctober 2, 2026clicks digital GmbH Information Listed by Rhysida Ransomware GroupSeptember 30, 2026Law Offices of R. David Williams, P.A. Listed by Rhysida Ransomware GroupSeptember 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Electro Heat Sweden AB Listed by Rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram