interfides.de Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The interfides.de Listed by lockbit3 Ransomware Group (reported May 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 9 May 2023, the German tax-advisory firm interfides.de appeared on a leak site operated by the ransomware group known as lockbit3. Public reporting states that internal files were exfiltrated in a ransomware attack; the number of people affected remains unknown, and further technical details have not been disclosed.
Because the firm advises foreign clients with business interests in Germany, any exposure of internal material carries potential consequences for clients, partners and the organisation itself. What is confirmed so far is limited to the listing itself and the description of exfiltrated internal files.
Breaking down the breach
According to available records, interfides.de was listed by lockbit3 on 9 May 2023. The sole concrete description of the incident is that internal files were allegedly exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the precise date the intrusion began, the initial access method, or the number of individuals whose information may be involved. Those elements remain undisclosed.
The listing on the group’s leak site constitutes a claim by lockbit3 that it holds data taken from the firm. Independent confirmation of the full scope or of any subsequent publication of the files has not been supplied in the material available. As with many ransomware incidents, the public record at this stage consists of the attribution, the reported date, and the high-level characterisation of the data as internal files.
Inside lockbit3
Lockbit3 is the name associated with a long-running ransomware operation that has appeared in numerous public incident reports since its earlier iterations. The group typically gains access to networks, steals data, encrypts systems, and then threatens to publish the stolen material on a dedicated leak site unless a ransom is paid. This double-extortion model—encryption plus the threat of data release—has been a consistent feature of its activity.
Public reporting over several years has documented lockbit3’s use of automated tools, affiliate recruitment, and high-volume targeting across multiple sectors and countries. The group’s leak site serves as both a pressure mechanism and a public claim of responsibility. In the present case, the appearance of interfides.de on that site is therefore best understood as lockbit3’s assertion that it conducted the attack and obtained internal files; the claim has not been independently verified beyond the listing itself in the facts at hand.
Who is interfides.de?
interfides Steuerberatungsgesellschaft mbH, operating as interfides.de, is a German tax-advisory practice established in 1978. It specialises in providing advisory services to foreign clients that maintain a business presence in Germany. Firms of this type routinely handle sensitive commercial, tax and personal information belonging to international businesses and their representatives.
Because the practice sits at the intersection of cross-border commerce and German tax compliance, a breach affecting its internal systems can have implications that extend beyond the firm’s own staff. Clients rely on such advisers to manage confidential filings, corporate structures and financial data; any compromise therefore raises questions about the confidentiality of those relationships.
The information in question
The only data category named in available reporting is “internal files exfiltrated in a ransomware attack.” No further inventory—such as specific document types, client lists, financial records or personal identifiers—has been publicly itemised. The exact contents therefore remain unconfirmed.
Organisations that provide tax and business advisory services to foreign clients typically hold correspondence, tax filings, corporate documents, identification details and financial information. It is reasonable to expect that material of that general nature could be among internal files, yet nothing in the public record confirms which, if any, of those categories were actually taken. Readers should treat any more granular claims as unverified until additional evidence appears.
Why it matters
For individuals and companies that have used interfides.de’s services, the principal risk is that confidential business or personal information could surface or be misused if the exfiltrated files are released or sold. Even without confirmed publication, the mere fact of exfiltration creates uncertainty about the continued secrecy of tax positions, corporate arrangements or identity documents.
For the firm itself, the incident carries operational, legal and reputational consequences. German data-protection rules require organisations to assess and, where necessary, notify affected parties and regulators. Clients may seek reassurance or alternative arrangements, and the firm must devote resources to containment, investigation and recovery. Because the number of people affected is unknown, the full scale of these obligations cannot yet be quantified from public sources.
In concrete terms, exposed parties face possible identity misuse, targeted phishing that references genuine advisory relationships, or commercial disadvantage if sensitive business details become known to competitors or adversaries. These risks are real but remain bounded by the limited public detail; speculation beyond the reported facts is not warranted.
What to do if you're exposed
If you have been a client or counterpart of interfides.de, monitor financial and tax-related accounts for unusual activity and treat unsolicited messages that reference the firm with caution. Consider placing fraud alerts with relevant credit or identity services where available, and retain copies of any official correspondence you receive from the firm about the incident.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Remaining alert to further official statements from the organisation or from regulators will help you decide whether additional steps become necessary as more information, if any, enters the public domain.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
davidsbridal.com Listed by lockbit3 Ransomware Groupmetalnet.nl Listed by lockbit3 Ransomware Groupaek.mk Listed by lockbit3 Ransomware Groupmsim.de Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the interfides.de Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.