Josef Saller Services eK - Saller Bau Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Josef Saller Services eK - Saller Bau Listed by alphv Ransomware Group (reported August 29, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continued through 2022 to target mid-sized firms across construction and real-estate supply chains, treating internal documents as leverage even when the precise scale of an intrusion remained opaque. In that climate, the appearance of a German building company on a dark-web leak site was one more data point in a pattern of opportunistic extortion rather than an isolated curiosity.
On 29 August 2022, the ransomware operation known as alphv publicly listed Saller Bau GmbH, also referenced in connection with Josef Saller Services eK. The group claimed it had exfiltrated internal files during a ransomware attack. No independent confirmation of the volume of data, the number of people affected, or the exact method of initial access has been released in public reporting. The listing itself therefore stands as an unverified claim, yet it is sufficient to warrant careful attention from anyone who has done business with the firm.
What happened
Public records state only that Saller Bau GmbH was named on alphv’s leak site on 29 August 2022. The sole description of the material involved is “internal files exfiltrated in a ransomware attack.” No figure for the quantity of data, no list of file names, no timeline of the intrusion, and no statement confirming whether systems were encrypted or merely copied have been disclosed. The number of individuals potentially affected remains unknown. In short, the incident is documented solely through the threat actor’s own claim and the sparse contemporaneous summary that the company operates in the real-estate sector.
Inside alphv
Alphv, widely tracked by researchers as the BlackCat group, emerged in late 2021 as a ransomware-as-a-service operation. It is known for a Rust-based encryptor, double-extortion tactics that combine system encryption with data theft, and a Tor-hosted leak site used to pressure victims. Affiliates typically gain initial access through compromised credentials, phishing, or unpatched remote-access services, then move laterally before exfiltrating selected files and deploying ransomware. The group has previously claimed responsibility for attacks on manufacturing, logistics, and professional-services firms across Europe and North America. Its public statements about any single victim, including Saller Bau GmbH, are claims advanced for extortion purposes and should be treated as such until corroborated by the organisation or by independent forensic reporting.
Who is Saller Bau GmbH?
Saller Bau GmbH is a German company active in the real-estate and construction sector. Firms of this type routinely manage project documentation, contractor and subcontractor records, building plans, financial ledgers, and correspondence with clients, suppliers, and local authorities. They may also hold employee personnel files and, in some cases, limited personal data belonging to property owners or tenants. A breach at such an organisation matters because the documents involved can reveal commercial negotiations, pricing structures, site security details, and personal identifiers that retain value long after any ransom deadline has passed. Even without confirmed proof of widespread personal-data exposure, the mere listing raises legitimate questions for partners and staff who rely on the confidentiality of those records.
What was likely exposed
The only data type named in available reporting is “internal files” said to have been taken during the ransomware incident. No inventory of those files has been published, nor has any confirmation that customer, employee, or financial records were among them. Organisations in real estate and construction typically store contracts, invoices, architectural drawings, email archives, and human-resources material. It is therefore possible that some combination of commercial and personal information was copied, yet the exact contents remain unconfirmed. Readers should treat any more specific assertion as speculation until the company or competent authorities provide further detail.
Why it matters
For individuals, the practical risks centre on secondary misuse of any personal or financial details that may have been present in the stolen files—targeted phishing, invoice fraud, or identity misuse. For the company, the consequences include potential regulatory scrutiny under European data-protection rules, disruption of ongoing projects, and erosion of trust among clients and suppliers. Because the number of people affected is unknown and the precise data types are undisclosed, the full scope of harm cannot yet be measured. What is clear is that ransomware groups continue to monetise even modest collections of internal documents, and the absence of public metrics does not equate to an absence of risk.
Were you affected?
If you have worked with, been employed by, or supplied services to Saller Bau GmbH or related Josef Saller entities, treat the alphv claim as a prompt for basic hygiene rather than proof of personal compromise. Monitor bank and credit statements for unfamiliar activity, be wary of unexpected emails or calls that reference construction projects or invoices, and consider placing fraud alerts with relevant credit agencies if you believe sensitive identifiers were shared with the firm. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Should any organisation formally notify you of confirmed exposure, follow the specific guidance in that notice and retain copies for your records.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Cappagh Contractors Construction (London) Ltd Listed by alphv Ransomware GroupUnique Engineering is the most collaborative and dangerous construction company in Asia Listed by alphv Ransomware GroupGrupo Garza Ponce was hacked! Due to a massive company vulnerability, more than 2 TB of se Listed by alphv Ransomware GroupBaumschlager Hutter Partners - Business Information Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.