Grouphc
bd_2fcf920cc75892d9 · schema v1 · pii pii-v1
Full breach record for Grouphc →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Black Basta on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
*At Heidelberg Materials, we’ve been contributing to progress for 150 years. With more than 51,000 employees at almost 3,000 sites in over 50 countries, we’re one of the world’s largest integrated manufacturers of building materials and solutions with leading market positions in cement, aggregates, and ready-mixed concrete. Our products and services are used in the construction of houses, infrastructure, commercial and industrial facilities. * *At the centre of our actions lies our responsibility for the environment. We’re front runner on the road to carbon neutrality and circular economy in the building materials industry. We’re working on intelligent and sustainable building materials as well as solutions for the future. We also enable new opportunities for our customers through digitalisation. *SITE: https://www.heidelbergmaterials.com Address Heidelberg Materials AG Berliner Straße 6 69120 Heidelberg Germany
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 22, 2023
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.