On February 24, 2025, the German software company HOST Software Entwicklung und Consulting GmbH appeared on the leak site of the qilin ransomware group. The listing indicates that internal files were exfiltrated during a ransomware attack on the developer of Ulysses ERP and MES software, which serves manufacturing SMEs in sectors such as plant construction, steel, and sheet metal work. Customers and partners whose information may have been stored in the company’s systems are now at risk of identity exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch HOST Software Entwicklung und Consulting GmbH
Get alerted the next time HOST Software Entwicklung und Consulting GmbH files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about HOST Software Entwicklung und Consulting GmbH’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves data exfiltration rather than simple encryption. The qilin leak site lists HOST Software as a victim and provides samples of the stolen material. No exact victim count has been published, and the precise volume of data remains unclear. The company develops business software that handles sensitive operational records for small and mid-size manufacturers, so the exposed files could contain customer contracts, employee details, financial information, or technical configurations.
Available reporting describes the attack as following the group’s typical pattern: initial access, data theft, and subsequent extortion pressure. As of the publication date on the leak site, the company had not made any public statement confirming or denying the breach.
Why This Matters for You and Your Family
Even if you never bought Ulysses software directly, your personal or financial data may have been stored by a manufacturer that did. Suppliers, vendors, and service providers often keep copies of contracts, invoices, tax IDs, addresses, and contact details. When those records are stolen, the information can be sold or published, giving criminals an easy way to target you with phishing, identity theft, or harassment.