BÜCHNER BARELLA Holding
bd_6aae1b1a3da4fd00 · schema v1 · pii pii-v1
Full breach record for BÜCHNER BARELLA Holding →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedBackgrounds unclear: Cyberattack on insurance broker Büchner Barella. Büchner Barella: The German insurance group Büchner Barella was the victim of a targeted and criminal cyberattack by hackers, but the company's security systems helped limit the damage. The hackers managed to compromise the systems, but the company is working with experts to resolve the issue. The details of the attack are still unknown, but the company will inform its clients as soon as possible. Linked ransomware group: lynx.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 17, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitelynxbd_151e7f00d80d90952025-08-27 · +10dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lynx
According to ransomware.live, Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.