The ransomware payload, operating under the “payload” threat actor, breached Qualiflex Datacenter (CH) and exfiltrated data from multiple organizations including HWZ-Studiengänge (fh-hwz.ch), myenb.ch, schelling.ch, kaelteringag.ch, kaeltebucher.ch, cbmswiss.ch, vitabad.ch, and ign8.ch. The stolen data was taken from these targets in Switzerland. #Switzerland
Incident Details
- Victim: Qualiflex Datacenter | HWZ-Studiengnge (fh-hwz.ch), myenb.ch, etc
- Sector: Technology
- Country: CH
- Actor: payload
- Source: http://payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion/posts/33d6a45b-360e-4c37-b5dc-141a87b54a19
- Discovered: 2026-08-20T17:26:46.782348+00:00
- Published: 2026-08-20T17:26:05.068448+00:00
Information
- Data from companies such as HWZ-Studiengänge (fh-hwz.ch), myenb.ch, schelling.ch, kaelteringag.ch, kaeltebucher.ch, cbmswiss.ch, vitabad.ch, ign8.ch, and others was stolen from Qualiflex Datacenter.

Disclaimer: This post is based on public claims made by the ransomware group "payload". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.