On October 3, 2025, German automation firm Rihatec Systemlösungen appeared on the leak site of the qilin ransomware group, with internal files reportedly exfiltrated during a ransomware attack. The Munich-based company builds control cabinets and automation solutions for industrial machines and serves clients across the DACH region. While the exact number of individuals whose data may have been exposed remains unknown, any customer, supplier, or employee whose personal or business records were stored in Rihatec’s systems could now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Rihatec Systemlösungen
Get alerted the next time Rihatec Systemlösungen files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Rihatec Systemlösungen’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin actors gained access to Rihatec’s network, encrypted systems, and copied internal files before publishing a sample on their leak portal. The data includes internal files that ransomware groups typically use for extortion. No confirmed total of records or specific victim count has been released. The listing carries the standard qilin deadline pressure: pay or face full publication of the stolen archive.
Why This Matters for You and Your Family
When a supplier or service provider in your supply chain is breached, your information can travel with it. If you or your family have interacted with Rihatec — as a customer, vendor, job applicant, or through any shared business contact — details such as names, addresses, phone numbers, email accounts, or contract information may have been taken. Once exposed, that data rarely stays isolated. It can appear on dark-web markets within weeks, giving identity thieves, stalkers, or scammers a direct route to you.
Credential leaks like this one often cascade far beyond the original victim company. Passwords or email addresses reused across personal accounts become entry points for takeovers of online banking, email, social media, and even children’s gaming profiles.