Planungsgruppe M+M AG
auroraThis record tracks a ransomware attack claimed by the aurora group against Planungsgruppe M+M AG. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.
Window Zero
EXPOSURE GAPWindow Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.
Attack Summary
Planungsgruppe M+M AG is a German Aktiengesellschaft headquartered in Böblingen, Baden-Württemberg, with approximately 432 employees across 10 offices (Böblingen, Stuttgart, München, Nürnberg, Regensburg, Ingolstadt, Augsburg, Esslingen, Mannheim, Frankfurt). Annual revenue: approximately €52 million. The firm provides architecture, urban planning, structural engineering, building physics, fire protection, BIM, landscape planning, and interior design services. Over 5,200 projects completed across decades of operation. The exfiltrated dataset spans two complete file servers (MMBB04, MMBB05), plus the DATEV financial processing archives, SFirm banking software databases, the ELO document management system, Outlook email archives (PSTs), and payroll/HR data — a total of 268 GB across approximately 124,000 files, covering 2006 to 2026.
Leak Screenshots
1 CAPTUREDCaptured directly from the operator's leak site by our collector, last checked 2026-09-02. Verdict evidence: [M1] Files (8) with download links for SHA256SUMS.txt, Zugangsdaten_AzubMe.txt, DATEV.RDP, Zugangsdaten_JHK-Portal.docx, Zugangsdaten_Givve-Portal.docx, Zugangsdaten_Persis_Confluence.docx, Zugangsdat
Capture history — 2 day(s) tracked. Content is locked.