LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › tilg.at Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

tilg.at Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 19, 2023
tilg.at Listed by lockbit3 Ransomware Group

Reported June 19, 2023.

HIGH
Severity
June 19, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The tilg.at Listed by lockbit3 Ransomware Group (reported June 19, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On June 19, 2023, the organisation tilg.at was listed by the ransomware group known as lockbit3. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further specifics about the incident have not been disclosed.

The listing places tilg.at among organisations whose data the group claims to have taken. For customers, partners, and others connected to the firm, the episode raises practical questions about what may have been exposed and what steps are warranted while details stay limited.

Breaking down the breach

According to the available record, tilg.at appeared on a lockbit3 listing dated June 19, 2023. The reported summary describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No confirmed figure for the volume of data, no technical description of the intrusion method, and no timeline of when systems were first accessed have been made public. The number of individuals potentially affected is listed as unknown.

Ransomware incidents of this type typically involve unauthorised access followed by encryption of systems and the removal of copies of data. In this case, the public facts stop at the claim of exfiltration of internal files. Whether a ransom demand was issued, whether negotiations occurred, or whether any data has been released beyond the listing itself is not stated in the available information. The record therefore establishes only that the organisation was named by the group and that internal files are described as having been taken.

The group behind it: lockbit3

Lockbit3 is a well-documented ransomware operation that has appeared in numerous public incident reports over recent years. The group commonly gains access to networks, steals data, encrypts systems, and then lists victims on a leak site while threatening to publish the material if payment is not made. Its model has often involved affiliates who carry out intrusions under a shared brand and infrastructure.

Public knowledge of lockbit3 includes a pattern of high-volume targeting across sectors and geographies, frequent use of double-extortion tactics, and periodic updates to its tooling and leak-site presentation. In the present matter, the group’s listing of tilg.at constitutes a claim that it holds data from the organisation. No independent confirmation of the full scope of that claim is contained in the facts provided here, so the listing is treated as an assertion by the actors rather than verified fact.

Who is tilg.at?

tilg.at is identified in the reporting as a business focused on high-quality window systems, individual sun-protection solutions, whole-glass constructions and conservatories, front doors and interior doors, and professional assembly using current techniques. Organisations of this kind typically operate in the building-products and construction-supply sector, serving residential and commercial clients with manufactured components and installation services.

Companies in this field commonly hold customer contact details, project specifications, supplier records, employee information, financial and invoicing data, and internal operational documents. A breach involving such an organisation is consequential because it can touch both commercial relationships and the personal information of private individuals who have ordered products or services. The .at domain indicates an Austrian connection, placing the firm within a European regulatory environment that includes data-protection obligations, though the facts of this incident do not address compliance status.

The information in question

The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No inventory of specific data categories—such as names, addresses, financial records, or employee files—has been published in the available record. Exact contents therefore remain unconfirmed.

Organisations that design, supply, and install windows, doors, glass structures, and sun-protection systems ordinarily maintain customer order histories, delivery and installation addresses, correspondence, contracts, supplier catalogues, payroll and personnel files, and internal technical or commercial documents. Any of these could fall under the broad description of internal files. Because the public account does not itemise what was taken, it is not possible to state with certainty which of these typical holdings, if any, were involved.

What's at stake

For individuals whose information may have been among the internal files, the concrete risks include unwanted contact, phishing attempts that reference genuine project or order details, and the possibility that personal or financial data could be misused if it was present. Even limited internal documents can supply enough context for social-engineering attacks aimed at customers or staff.

For the organisation itself, the stakes include operational disruption from the ransomware event, potential contractual or regulatory follow-up, and the longer-term task of verifying what left its systems. Because the scale of the exfiltration and the precise data types are undisclosed, both the individual and organisational impact remain difficult to quantify from public sources alone. The absence of a confirmed affected-person count further limits any precise assessment of breadth.

If your data was in this claimed breach

If you have been a customer, employee, or partner of tilg.at, treat the possibility of exposure seriously while recognising that public detail is limited. Monitor financial and email accounts for unusual activity, be cautious of unexpected messages that reference windows, doors, glasswork, or installation projects, and consider changing passwords on any accounts that may have shared credentials or recovery information with the firm. Retain records of any suspicious contact.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Doing so provides one practical way to see whether your details appear in previously recorded incidents and to decide on further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companytilg.at security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See tilg.at’s full breach history →

More recent breaches

triaflex.at Listed by lockbit3 Ransomware GroupMay 3, 2023hasenauer-anlagenbau.at Listed by lockbit3 Ransomware GroupMay 2, 2023wittmann.at Listed by lockbit3 Ransomware GroupJanuary 21, 2024contimade.cz Listed by lockbit3 Ransomware GroupDecember 30, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the tilg.at Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram