Quick Summary
AllegedExecutive Summary
Berlin Brandenburgische Wohnungsbaugenossenschaft, a German residential housing cooperative operating under the domain bbwbg[.]de, was listed by the Qilin ransomware group on its leak site on August 18, 2026. The organization, which operates in the Berlin-Brandenburg region, is in the real estate sector. This listing is notable as Qilin typically targets manufacturing and commercial enterprises, suggesting the group applies a broad scope in its victimology without strict sectoral preferences. Qilin has been highly active, claiming 184 victims in the 60 days preceding this listing. The group’s primary targets are in the Manufacturing, Professional Services, and Business Services industries, with a strong presence in the United States, Germany, and France. Other recent German victims identified include EmpireWorks, Urban Worldwide, United Association Local Union 345, and Crown Group. The inclusion of Berlin Brandenburgische Wohnungsbaugenossenschaft, a cooperative housing entity, represents a departure from Qilin’s usual targeting patterns.
Technical Analysis
SOCRadar’s analysis of stealer-log data for bbwbg[.]de returned no records within the sampled dataset. It is important to note that this query was paginated, and records may exist under alternate corporate domains or associated email aliases that were not captured in this specific search. Therefore, the absence of positive findings in this sample does not definitively confirm that the organization is unaffected by credential compromise. Qilin ransomware operators frequently leverage stolen credentials obtained from underground marketplaces to gain initial access to victim networks. This often involves compromising credentials for VPN services or Microsoft 365 portals, which then facilitates the deployment of ransomware. The null result from the stealer-log query does not preclude this common intrusion pathway for the Qilin group.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.