Ransom! Planungsgruppe M+M AG (AUG-2026)

Ransom! Planungsgruppe M+M AG (AUG-2026)
aurora ransomware targeted Planungsgruppe M+M AG (CH), exfiltrating data from two file servers (MMBB04, MMBB05) along with DATEV financial archives, SFirm banking databases, the ELO document management system, Outlook PST email archives, and payroll/HR records. The leaked dataset totaled 268 GB across ~124,000 files covering 2006–2026, impacting #Switzerland

Incident Details

  • Victim: Planungsgruppe M+M AG
  • Sector: Professional Services
  • Country: CH
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/planungsgruppe-mm-ag-3eb2a03f
  • Discovered: 2026-08-17T16:22:52.792149+00:00
  • Published: 2026-08-17T00:00:00+00:00

Information

  • The exfiltrated data reportedly includes two complete file servers (MMBB04, MMBB05), along with DATEV financial processing archives, SFirm banking software databases, ELO document management system data, Outlook email archives (PSTs), and payroll/HR records.
  • In total, the leak is said to comprise 268 GB across approximately 124,000 files.
  • The covered timeframe of the exposed data ranges from 2006 to 2026.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live