All ransomware incidents
Ransomware group sarcoma hits Söllner
Söllner — a construction target operating in DE has been listed by the sarcoma ransomware group on 2025-11-20. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Söllner |
|---|---|
| Threat Group | sarcoma |
| Summary | Söllner Söllner GmbH & Co. KG is a family-owned roofing company based in Plettenberg, operating for four generations since 1902. The company specializes in roofing, carpentry, facade construction, scaffolding, and offers additional services such as container service and crane rentals. Recently, they have expanded into architecture, providing comprehensive services from design to execution. With a team of qualified professionals, Söllner serves both regional and national clients in the industrial, commercial, public, and private sectorsGeo: Germany - Leak size: 286 GB Archive - Contains: Files, SQL |
| Date of Breach | 2025-11-20 |
| Discovery Date | 2025-11-20 |
| Region | DE |
| Target Domain | soellner.de |
| Business Sector | Construction |
| Severity | MEDIUM |
Claim by sarcoma
Söllner Söllner GmbH & Co. KG is a family-owned roofing company based in Plettenberg, operating for four generations since 1902. The company specializes in roofing, carpentry, facade construction, scaffolding, and offers additional services such as container service and crane rentals. Recently, they have expanded into architecture, providing comprehensive services from design to execution. With a team of qualified professionals, Söllner serves both regional and national clients in the industrial, commercial, public, and private sectorsGeo: Germany - Leak size: 286 GB Archive - Contains: Files, SQL
Posted by the sarcoma threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

