All ransomware incidents
Ransomware group sarcoma hits Paul Hildebrandt
Paul Hildebrandt — a manufacturing target operating in DE has been listed by the sarcoma ransomware group on 2025-11-11. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Paul Hildebrandt |
|---|---|
| Threat Group | sarcoma |
| Summary | Paul Hildebrandt Paul Hildebrandt AG is a leading packaging company offering over 50,000 products, including environmentally friendly options. With 300 employees across 14 locations in Germany, Austria, and Denmark, they provide tailored packaging solutions for a variety of industries. The company emphasizes sustainability and efficient packaging processes as part of their commitment to client solutions. Their diverse product range includes films, boxes, adhesive tapes, and various packaging materials.Geo: Germany - Leak size: 1,4 TB Archive - Contains: Files, SQL, Exchange |
| Date of Breach | 2025-11-11 |
| Discovery Date | 2025-11-11 |
| Region | DE |
| Target Domain | hildebrandt.de |
| Business Sector | Manufacturing |
| Severity | MEDIUM |
Claim by sarcoma
Paul Hildebrandt Paul Hildebrandt AG is a leading packaging company offering over 50,000 products, including environmentally friendly options. With 300 employees across 14 locations in Germany, Austria, and Denmark, they provide tailored packaging solutions for a variety of industries. The company emphasizes sustainability and efficient packaging processes as part of their commitment to client solutions. Their diverse product range includes films, boxes, adhesive tapes, and various packaging materials.Geo: Germany - Leak size: 1,4 TB Archive - Contains: Files, SQL, Exchange
Posted by the sarcoma threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

