HackerFeeds
All ransomware incidents
soellner.de

Ransomware group sarcoma hits Söllner

MEDIUM
·Construction·DE·2025-11-20

Söllner — a construction target operating in DE has been listed by the sarcoma ransomware group on 2025-11-20. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationSöllner
Threat Group
sarcoma
SummarySöllner Söllner GmbH & Co. KG is a family-owned roofing company based in Plettenberg, operating for four generations since 1902. The company specializes in roofing, carpentry, facade construction, scaffolding, and offers additional services such as container service and crane rentals. Recently, they have expanded into architecture, providing comprehensive services from design to execution. With a team of qualified professionals, Söllner serves both regional and national clients in the industrial, commercial, public, and private sectorsGeo: Germany - Leak size: 286 GB Archive - Contains: Files, SQL
Date of Breach2025-11-20
Discovery Date2025-11-20
RegionDE
Target Domainsoellner.de
Business SectorConstruction
Severity
MEDIUM

Claim by sarcoma

Söllner Söllner GmbH & Co. KG is a family-owned roofing company based in Plettenberg, operating for four generations since 1902. The company specializes in roofing, carpentry, facade construction, scaffolding, and offers additional services such as container service and crane rentals. Recently, they have expanded into architecture, providing comprehensive services from design to execution. With a team of qualified professionals, Söllner serves both regional and national clients in the industrial, commercial, public, and private sectorsGeo: Germany - Leak size: 286 GB Archive - Contains: Files, SQL

Posted by the sarcoma threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.