Kochs GmbH
About the organisation
[manufacturer] *** β a family-owned German manufacturer of windows, doors, and aluminium faΓ§ade systems headquartered in Herzogenrath, Nordrhein-Westfalen, with ~240 employees across Germany, the Netherlands, and Hungary. The exposed material includes: 22 GB of payroll database backups (7 MSSQL .bak files, 2016β2023) β every employee's salary, bank IBAN, tax class, social insurance number, pension contributions, and wage garnishments. 2.3 GB of DATEV payroll records (through May 2026) β individual named salary documents, garnishment data, company car records for all three entities. 7 Active Directory passwords in plaintext batch scripts β including both Managing Directors, with one MD's credentials spanning three separate AD domains. 28+ proprietary application source code repositories β WinPro ERP, Apertum CRM, MES integrations, production viewers, time-tracking, and rack-management systems. Each one hardcodes its database credentials. SSL/TLS private keys for kochs.de (2021β2026) β enabling domain impersonation and man-in-the-middle attacks. 77 VPN pre-shared keys from the LANCOM gateway configuration β the complete remote-access roster since 2018. Managing Director's MRI and X-ray scans β brain and spine medical imaging, GDPR Art. 9 special category health data. 16 named employee disciplinary records, 11 driver's license scans, attorney-client privileged litigation files from two active employment lawsuits. Complete financial records β 2024 annual accounts, P&L, balance sheets, SFirm banking database, Syska ProFI general ledger, cost accounting through December 2024.
What the listing means
Kochs GmbH appeared on the aurora leak site on 22 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 1 claim in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Kochs GmbH as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account on Kochs GmbH, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Manufacturing organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/S29jaHMgR21iSEBhdXJvcmE=
Show leak-site screenshot
Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.