Ransomware Group aurora Hits: GILDE Handwerk Macrander GmbH and Co. KG
Summary
In the latest cybersecurity news, GILDE Handwerk Macrander GmbH & Co. KG — an organization based in DE — has fallen victim to a ransomware attack conducted by the group aurora. This data breach, discovered on 2026-08-04T06:21:33.166294+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | GILDE Handwerk Macrander GmbH & Co. KG |
| Threat Group | aurora |
| Summary | [wholesale] GILDE Handwerk Macrander GmbH & Co. KG is a family-owned German Mittelstand group headquartered in Bocholt, Nordrhein-Westfalen. The GILDE Gruppe operates across wholesale trade in gifts, home accessories, and furniture through brands including GILDE Handwerk, Fink Living, and HAKU Möbel, with 50+ legal entities spanning Germany, Austria, the Netherlands, France, the UK, and Hong Kong.
The exposed material includes: 148+ personal ID document scans — Personalausweise (national ID cards), Reispässe (passports), Führerscheine (driver’s licences), and Heiratsurkunden (marriage certificates) for employees, directors, and family members. Names range from warehouse staff to the CEO. Full employee payroll records (2006–2025) — tax IDs (Steuer-IDs), social security numbers, bank accounts, salary details, sick notes (Krankmeldungen), and disciplinary records for an estimated 200–400 current and 200–500 former employees across all entities. |
| Date of Breach | 2026-08-04T00:00:00+00:00 |
| Discovery Date | 2026-08-04T06:21:33.166294+00:00 |
| Region | DE |
| Target Domain | GILDE Handwerk Macrander GmbH & Co. KG |
| Business Sector | Manufacturing |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- realistic phishing tests — close the gap attackers exploit.
- train staff to spot attacks — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
