Badisches Landesmuseum
bd_f949f17d5457edb8 · schema v1 · pii pii-v1
Full breach record for Badisches Landesmuseum →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedCyberattack on the Badisches Landesmuseum in Karlsruhe. Badisches Landesmuseum: The Badisches Landesmuseum in Karlsruhe was the victim of a cyberattack, the consequences of which were discovered on June 19, 2026. The attack resulted in the theft of data (professional and personal) belonging to staff members, partners, and visitors. To contain the damage, the IT infrastructure was immediately taken offline. The museum has filed a complaint and is cooperating with the relevant authorities to manage the crisis and restore systems. Linked ransomware group: safepay.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 19, 2026
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitesafepaybd_63c5cc4a896bcf212026-07-27 · +38dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
safepay
According to ransomware.live, SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.