LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › rottner-tresor.at Listed by Settra Ransomware Group

HIGH severityUnverified claimHow we verify

rottner-tresor.at Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 17, 2026
rottner-tresor.at Listed by Settra Ransomware Group

Occurred August 2026 · publicly disclosed September 17, 2026.

HIGH
Severity
September 17, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

rottner-tresor.at was listed by the Settra ransomware group on 17 September 2026. The group claims to hold data belonging to an undisclosed number of people; anyone who may have interacted with the site should check for updates and consider changing any passwords or enabling additional account protections.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 17, 2026, the ransomware group Settra listed rottner-tresor.at on its leak site, presenting the Austrian firm Rottner Tresor GmbH as a claimed victim. Public detail is limited: the listing does not state how many people might be affected, does not inventory data types in a clear way, and offers only a fragmentary description of sample material. As of writing, the company has not publicly confirmed the claim.

A leak-site entry is an accusation and a pressure tactic, not an independent verification. What follows separates what the listing asserts from what remains undisclosed, and outlines conditional steps readers can take if their information were ever involved.

Inside the listing

According to the Settra listing, the target is identified as rottner-tresor.at / Rottner Tresor GmbH. The reported date associated with the public claim is September 17, 2026. The number of people potentially affected is unknown, and the listing does not disclose a structured catalogue of data categories.

The reported summary on the listing refers to documents and includes fragmentary wording such as “Rottner Tresor GmbH PROLOGUE” and a reference to an invoice for a 60-minute general anesthesia procedure. That text appears to be attacker-side marketing or a teaser snippet, not a confirmed archive inventory. Method of intrusion, encryption events, ransom demands, timelines inside the network, and whether any files were actually copied remain undisclosed in the material provided for this report. Nothing in the public claim has been independently verified here.

The group behind it: Settra

Settra is known in public reporting as a ransomware and extortion-style actor that pressures organisations by threatening to publish material on a dedicated leak site. Like other groups in this category, it typically combines claims of network access with timed publication threats intended to force negotiation. Well-documented patterns for such crews include double-extortion messaging—alleging both disruption and data theft—though each listing must be treated on its own terms.

For this specific case, only what appears on the listing should be attributed to Settra: the group has named rottner-tresor.at and has posted a short, incomplete document-oriented teaser. No further Settra statements unique to this victim are established in the facts available for this article. Leak-site posts can be exaggerated, recycled, incomplete, or false; they establish that a claim was published, not that every assertion is accurate.

About rottner-tresor.at

Rottner Tresor GmbH, associated with the rottner-tresor.at presence, operates in the security-products sector, commonly linked to safes, secure storage, and related commercial offerings for homes and businesses. Firms in this space typically maintain customer and dealer records, order and invoice systems, warranty and service histories, and internal administrative files. Some also hold logistics, payment-related, or B2B contract data depending on how they sell and support products.

A claimed incident involving such an organisation matters because trust and confidentiality sit close to the product itself: customers buy physical security and expect careful handling of their commercial and personal details. A leak-site listing does not by itself prove a breach occurred, but it does create uncertainty for customers, partners, and staff until the company or independent authorities clarify the situation. Public confirmation from the organisation was not part of the material available for this report.

What data was at risk

The facts state that data types named as exposed are not disclosed. The listing’s teaser language points at “documents” and an invoice-style fragment, including wording about a medical-procedure invoice that does not clearly match a safes retailer’s ordinary product line; that mismatch is a reminder that attacker descriptions can be partial, misleading, or taken out of context. Exact contents are unconfirmed.

If files were taken from a company of this kind, organisations in retail and secure-storage supply typically hold items such as customer contact details, delivery addresses, purchase and invoice records, dealer or partner lists, and internal correspondence. Whether any of those categories—or unrelated files—were involved in this claim is not established. Readers should treat any specific “what was allegedly stolen” narrative as unverified unless the company or a regulator later publishes a clear notice.

The real-world impact

For individuals and businesses that deal with Rottner Tresor, the practical risk is conditional. If customer or partner records were copied, possible outcomes include targeted phishing that references real orders or invoices, attempts to reset accounts using known email addresses, or misuse of phone and address data for social engineering. Invoice and order details can make fraudulent messages look legitimate. If only internal or unrelated documents were involved—or if the listing overstates access—the direct consumer impact could be limited. That distinction cannot be settled from the leak-site claim alone.

For the organisation, a public extortion listing can mean reputational strain, customer questions, and the cost of investigation whether or not the full claim is accurate. People affected remains unknown, so scale cannot be stated. The listing does not establish negligence, security architecture failures, or response quality; it establishes only that Settra published a named claim on its site.

What to do now

Because the incident is an unconfirmed listing, action should stay proportional and conditional: prepare as if misuse of business-contact or order data is possible, without assuming your information is already public.

Settra’s listing of rottner-tresor.at on September 17, 2026, is a public accusation with sparse detail—unknown affected population, undisclosed data categories, and only a fragmentary document teaser. The company has not publicly confirmed the claim as of writing. Until clearer official information appears, calm monitoring and basic account hygiene remain the most useful steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyrottner-tresor.at security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See rottner-tresor.at’s full breach history →

More recent breaches

fchhotels.com Listed by Settra Ransomware GroupSeptember 17, 2026pacificabs.com Listed by Settra Ransomware GroupSeptember 17, 2026sym.com.mx Listed by Settra Ransomware GroupSeptember 17, 2026naturesplus.com Listed by Settra Ransomware GroupSeptember 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the rottner-tresor.at Listed by Settra Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by settra — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram