ssp-ce.de Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ssp-ce.de was listed by the dragonforce ransomware group on March 26, 2026, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check the site or contact ssp-ce.de to see whether your data is involved and what steps to take.
Inside the incident
The available record states that internal files were exfiltrated during a ransomware attack. No confirmed date of intrusion, duration of access, or total quantity of data has been disclosed. The group’s listing on its leak site constitutes the primary public indication that material was taken; independent verification of the claim remains unavailable.
The group behind it: dragonforce
Dragonforce is a ransomware operation that has appeared in multiple public incident reports since at least 2023. The group typically uses encryption combined with data exfiltration to pressure victims. Its leak sites serve as a platform to publish names of organizations it claims to have targeted. In this case the group claims ssp-ce.de among its listings, but no additional statements or evidence specific to the company have been published by the actors.
ssp-ce.de and its sector
SSP Airport Gastronomiegesellschaft mbH is headquartered in Eschborn, Hesse, and employs between 250 and 499 people. The company generates annual revenue between $50 million and $100 million while providing food and beverage services at airports. Organizations in this sector routinely process supplier contracts, employee records, operational schedules, and passenger-related service data.
What data was at risk
The only detail released is that internal files were removed. No inventory of file categories, no confirmation of personal data, and no statement on whether customer or employee records were included has been made public. Exact contents therefore remain unconfirmed.
Why it matters
Airport service providers hold operational and personnel information whose exposure can affect business continuity and individual privacy. When such material appears in ransomware claims, affected organizations must determine whether regulatory notification or customer communication is required under applicable data-protection rules.
Were you affected?
- Monitor official statements from SSP Airport Gastronomiegesellschaft mbH for any customer or employee notifications.
- Review bank and service accounts for unusual activity if you have been a customer or employee.
- Use a free exposure scan of your email address against known breach datasets to check for unrelated appearances of your information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Greenway Technologies Listed by dragonforce Ransomware Grouphive360.com Listed by dragonforce Ransomware GroupAptora Listed by dragonforce Ransomware GroupREHA-ACTIV Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ssp-ce.de Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.