Küng Ag Bern Listed by noescape Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Küng Ag Bern Listed by noescape Ransomware Group (reported September 10, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target mid-sized industrial and wholesale firms across Europe, using data theft and public leak-site pressure as leverage even when operational disruption is limited. Listings on criminal forums and dedicated leak sites have become a routine feature of this landscape, often appearing before independent confirmation of what was taken or how systems were reached.
On 10 September 2023, the organisation Küng Ag Bern was listed by the ransomware group known as noescape. Public reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected remains unknown, and further technical detail has not been disclosed. For customers, partners and staff connected to a regional mineral-oil wholesaler, any such claim warrants careful attention even while many specifics stay unconfirmed.
Inside the incident
According to the available record, Küng Ag Bern was named on 10 September 2023 in connection with activity attributed to the noescape ransomware group. The reported summary characterises the event as a ransomware attack that involved the exfiltration of internal files. No public figure has been given for the volume of data, the number of systems involved, or the precise date on which access first occurred. Methods of initial entry, dwell time, and whether encryption was also deployed on production systems are undisclosed.
The listing itself constitutes a claim by the group rather than an independently verified forensic finding. No confirmed count of affected individuals has been published, and the record does not identify specific file names, databases or business units. In the absence of those details, the incident is best understood as an asserted data-exfiltration event tied to a ransomware operation, with the scale and full contents still unconfirmed in open sources.
Inside noescape
noescape is a ransomware operation that became active in the public eye in 2023. Like several contemporary groups, it has followed a double-extortion model: encrypting systems where possible while also copying data and threatening to publish it on a dedicated leak site if payment is not made. The group has typically advertised victims across multiple sectors and geographies, using countdown timers and sample file releases to increase pressure. Affiliates or operators associated with the brand have been observed to favour relatively rapid listing once exfiltration is claimed.
Public reporting on noescape has described standard ransomware tradecraft—phishing or exploitation of exposed services for initial access, lateral movement, and the use of custom or commodity encryptors—though exact tooling can vary by intrusion. The group’s leak site has served as its primary channel for naming organisations and asserting that internal material was stolen. In the case of Küng Ag Bern, the appearance of the organisation’s name on that infrastructure is therefore a claim by noescape; it does not by itself confirm the completeness of the alleged theft or the accuracy of any accompanying description.
Küng Ag Bern and its sector
Küng Ag Bern operates in the wholesale trade and distribution of mineral oil products under the AVIA brand. Public descriptions of the business note significant storage capacity in the Bern area and a customer base that relies on fuel and related energy products. Firms of this type sit at the intersection of logistics, bulk commodity handling and regional energy supply. They routinely manage commercial contracts, delivery schedules, storage and safety documentation, and relationships with both business customers and upstream suppliers.
A breach affecting such an organisation is consequential because the sector handles commercially sensitive pricing and volume data, operational details about storage and transport, and personal or contact information belonging to employees, drivers and business counterparties. Disruptions or data exposure can affect supply continuity, contractual confidence and regulatory obligations around hazardous materials and environmental compliance. Even when the precise technical impact remains limited in public reporting, the mere assertion of internal-file theft raises practical questions for anyone whose information may have been held in those systems.
The information in question
The facts available state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as customer lists, employee records, financial documents, or operational schematics—has been disclosed in the public record. The number of people potentially affected is unknown.
Organisations engaged in mineral-oil wholesale and distribution typically hold a mix of commercial and personal data: customer and supplier contact details, order and delivery histories, invoicing and payment records, employee and contractor information, site access or safety documentation, and internal correspondence. Whether any of those categories were present among the files noescape claims to have taken has not been independently confirmed. Readers should therefore treat the exposed material as “internal files” of undetermined scope rather than assuming any specific document set was involved.
The real-world impact
For individuals, the primary risks are secondary misuse of contact or identity data if such material was included, and targeted phishing that references genuine business relationships with Küng Ag Bern or the AVIA network. Commercial partners may face competitive exposure if pricing, volumes or contract terms were among the files, and they may need to monitor for invoice fraud or altered payment instructions that exploit knowledge of existing relationships. The organisation itself faces the ordinary consequences of a claimed ransomware incident: investigative and recovery costs, possible regulatory notification duties, and reputational pressure arising from the public listing.
Because the count of affected people and the exact data categories remain unknown, it is not possible to quantify personal harm with precision. The prudent stance is to assume that internal business information left the organisation’s control and to watch for follow-on social-engineering attempts that leverage that fact. No public evidence has been offered that critical infrastructure operations were halted, yet the presence of storage and distribution activities means any residual access or leaked operational detail would still merit careful review by the company and its partners.
What to do if you're exposed
If you have a past or present relationship with Küng Ag Bern—as a customer, supplier, employee or contractor—treat unsolicited messages that reference the company or fuel deliveries with extra caution. Prefer known official channels when checking invoices or account details, and enable multi-factor authentication on email and financial accounts where available. Monitor bank and credit statements for unfamiliar activity and consider a credit freeze or fraud alert if you believe identity data may have been involved. Keep copies of any suspicious correspondence.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step does not confirm involvement in this specific incident, but it provides a practical baseline for further monitoring while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Schwob AG Listed by noescape Ransomware GroupGasmart Organization Listed by noescape Ransomware GroupKorea Petroleum Industries Company Listed by noescape Ransomware GroupKorea Petroleum Industrial Co. Ltd Listed by noescape Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Küng Ag Bern Listed by noescape Ransomware Group →
Publicly posted by noescape — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.