glatten.de Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
glatten.de was listed by the safepay ransomware group on September 15, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; anyone with accounts or data at the organisation should check for any notices and take appropriate security steps.
On 15 September 2025, the ransomware group known as safepay listed glatten.de on its leak site, claiming responsibility for a ransomware attack in which internal files were exfiltrated. Public detail remains limited: the number of people affected is unknown, and no further confirmation of the incident has been independently verified beyond the group's claim. The organisation linked to the listing is J. Schmalz GmbH, a long-established, family-run engineering firm based in Glatten that specialises in vacuum technology and automation for handling applications. For employees, partners and anyone who has dealt with the company, the listing raises the practical question of whether any personal or business information may have been exposed.
What is known so far is confined to the leak-site entry itself. No official statement from the organisation detailing the scope, timeline or method of the intrusion has been incorporated into the available record, and the precise contents of the claimed data set have not been independently catalogued in public reporting.
Breaking down the breach
According to the reported summary, safepay listed glatten.de after claiming to have conducted a ransomware attack that involved the exfiltration of internal files. The listing was reported on 15 September 2025. Beyond that date and the description of “internal files,” no further technical particulars—such as the initial access vector, the duration of the intrusion, the volume of data taken, or whether systems were encrypted—have been disclosed in the available facts. The number of individuals potentially affected is recorded as unknown. Because the information originates from the threat actor’s own leak site, it must be treated as an unverified claim until corroborated by the organisation or by independent forensic reporting.
Ransomware incidents of this type typically follow a double-extortion pattern: data is copied before encryption, and the threat of public release is used to pressure the victim. In this case the public record stops at the claim of exfiltration; no ransom demand figure, negotiation status or confirmation of encryption has been supplied in the facts provided.
Inside safepay
Safepay is a ransomware operation that became active in the public threat landscape in 2024. Like many contemporary groups, it is known for double-extortion tactics: operators gain access to a network, steal data, deploy ransomware to encrypt systems, and then threaten to publish the stolen material on a dedicated leak site if payment is not made. The group maintains a dark-web portal where it posts victim names and, in some cases, sample files or larger data dumps. Its targets have historically spanned manufacturing, engineering and mid-sized industrial firms across Europe and elsewhere, though each listing remains a claim until verified.
Public reporting on safepay has described the use of common initial-access methods such as compromised credentials or vulnerable remote-access services, followed by lateral movement and data staging. No specific technical indicators unique to the glatten.de listing have been released in the available facts, so any reconstruction of the attack chain for this particular incident would be speculative and is therefore omitted here.
glatten.de and its sector
glatten.de is associated with J. Schmalz GmbH, a family-run engineering company headquartered in Glatten, Germany. The firm specialises in vacuum technology and automation solutions used for material handling, gripping and process automation across manufacturing, logistics and related industrial sectors. Companies of this profile typically maintain extensive technical documentation, customer and supplier records, employee data, design files and operational correspondence. Because vacuum and automation systems often integrate into larger production lines, the firm’s partners and clients may include other manufacturers that rely on its components.
A breach involving an engineering supplier can therefore affect not only the organisation’s own workforce but also the confidentiality of commercial relationships and technical know-how shared with customers. In the industrial automation sector, the loss of internal files can raise concerns about intellectual property, contractual details and the personal data of staff and business contacts.
The information in question
The facts state only that “internal files” were exfiltrated in a ransomware attack. No inventory of specific data categories—such as names, contact details, financial records, design drawings or authentication credentials—has been published. Organisations of this type commonly hold employee personnel files, customer and supplier databases, engineering drawings, quality-control records and internal communications. Whether any of those categories were among the files claimed by safepay remains unconfirmed. Readers should therefore treat any assertion about particular data elements as speculative until an official disclosure or independent analysis is available.
The real-world impact
For individuals whose information may have been among the internal files, the principal risks are identity-related misuse, targeted phishing and, in some cases, fraud that leverages knowledge of employment or commercial relationships. Business partners face the possibility that contractual or technical details could be exposed, potentially affecting competitive position or requiring contractual notifications under data-protection rules. For the organisation itself, the consequences can include operational disruption, the cost of forensic investigation and remediation, regulatory reporting obligations, and reputational strain with customers and suppliers.
Because the scale of the claimed exfiltration and the exact data types remain unknown, the concrete impact on any single person or partner cannot yet be quantified. The absence of confirmed numbers does not eliminate risk; it simply means that affected parties must proceed on the basis of caution rather than certainty.
Were you affected?
If you have been an employee, contractor, customer or supplier of J. Schmalz GmbH or have used services linked to glatten.de, treat the listing as a prompt to review your own exposure. Monitor bank and credit accounts for unusual activity, enable multi-factor authentication on email and work-related accounts, and be alert to phishing messages that reference the company or its products. Change passwords that may have been reused across personal and professional services. Organisations that believe they may hold relevant data should follow their internal incident-response and legal-notification procedures.
As a practical first step, readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention while further official information is awaited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
setex-textil.de Listed by safepay Ransomware Groupmeyer-lift.de Listed by safepay Ransomware Groupjuliuskoch.com Listed by safepay Ransomware Groupdecor-metall.de Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the glatten.de Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.