On April 24, 2026, the German construction-equipment company Merlo Teleskoplader appeared on the LockBit 5 ransomware leak site with internal files listed for public download after the group claimed to have exfiltrated data during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch merlo.de
Get alerted the next time merlo.de files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about merlo.de’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that LockBit 5 posted a notice on its onion site referencing Merlo’s internal documents. The listing includes samples of allegedly stolen files, though the exact volume and full contents remain unconfirmed by the company. No customer database or payment-card information has been explicitly advertised in the initial post. The incident follows the typical ransomware pattern of encryption followed by data exfiltration and extortion. Available reporting describes the breach as still active on the leak portal with a countdown timer visible to visitors.
Why This Matters for You and Your Family
When a company that supplies equipment to construction firms, farmers, and logistics operators is breached, the exposed internal files can contain contracts, employee records, supplier details, and correspondence that indirectly reveal personal information about ordinary people. Employee names, email addresses, phone numbers, and sometimes home addresses or family contact details surface in these leaks. Once published, that information rarely disappears. If you or anyone in your household has worked with Merlo, bought their equipment, or had your details shared through a dealer or service partner, your data may now be circulating. Criminals do not need a massive customer list to cause damage; a single spreadsheet is often enough to start targeted phishing, identity theft, or harassment campaigns against you and your family.
The Doxxing and Identity-Chain Implications
Ransomware leaks like this one rarely stop at the first company. Exposed emails and usernames are cross-referenced against other breaches, creating long identity chains that link your work accounts to personal ones. A password or phone number found in Merlo’s files can unlock gaming accounts, social-media profiles, or online shopping logins. Public reporting shows these chains frequently lead to doxxing, where attackers publish home addresses, children’s names, or family photos to increase pressure. Gaming accounts belonging to you or your children are especially vulnerable because kids often reuse simple passwords or email addresses tied to a parent’s identity. The result is a cascade: one corporate breach becomes dozens of personal account takeovers and privacy violations that can last for years.