Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik
About the organisation
https://www.***.com/c/atlas-elektronik-gmbh/22289599 https://www.***.com/c/atlas-north-america-llc/346681852 https://www.***.com/c/thyssenkrupp-marine-systems/559786010 www.atlas-elektronik.com na.atlas-elektronik.com https://www.tkmsgroup.com/atlas-elektronik/ ThyssenKrupp Marine Systems of Germany (often abbreviated TKMS) is a group and holding company of providers of naval vessels, surface ships and submarines. It was founded when large industrial conglomerate ThyssenKrupp acquired Howaldtswerke-Deutsche Werft on January 5, 2005 TKMS Group is a leading provider of integrated system solutions in maritime defense technologies, catering to the complex requirements of modern navies. The company specializes in surface vessels, submarines, and advan Atlas Elektronik, founded in 1902 and headquartered in Bremen, Germany, is a marine electronics and systems business. It is involved in the development of integrated sonar systems for submarines and heavyweight torpedoes. 1TB+
What the listing means
Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik appeared on the thegentlemen leak site on 28 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated — the attack itself is dated 25 June 2026, 2 days before the listing. This group has published 134 claims in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik as suspicious — leaked data gets weaponised for phishing within days.
- If you hold an account on www.zoominfo.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Manufacturing organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/VGh5c3NlbmtydXBwIE1hcmluZSBTeXN0ZW1zIChUS01TKSBHbWJIIC8gQXR...