DisclosureLens
GLOBALMalwareManufacturingManufacturingRansomwareBlack BastaRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh

Rheinmetall AG

bd_4dba3879856c69de · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Apr 16, 2023

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Rheinmetall AG3 incidents on file

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Black Basta on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: ManufacturingDiscovered: 2023-05-20

Source: Ransomware.live

Post text · scraped from the leak site

As an integrated technology group, the listed company Rheinmetall AG, headquartered in Düsseldorf, stands for a company that is as strong in substance as it is successful internationally, and that is active in various markets with an innovative range of products and services. Rheinmetall is a leading international systems supplier in the defence industry and at the same time a driver of forward-looking technological and industrial innovations in the civilian markets. The focus on sustainability is an integral part of Rheinmetall’s strategy. The company aims to achieve CO2 neutrality by 2035.Through our work in various fields, we at Rheinmetall take on responsibility in a dramatically changing world. With our technologies, products and systems, we create the indispensable basis for peace, freedom and sustainable development: security.SITE: www.rheinmetall.com Address Rheinmetall Platz 140476 DusseldorfGermanyPhone: +49 211 473-01Fax: +49 [REDACTED-PHONE]

Incident timeline — mostly unverified

? — ?

Breach window unknown

Apr 16, 2023

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.