Quick Summary
AllegedExecutive Summary
Edacentrum, a company based in Germany, has been listed as a claimed victim on the Panzer ransomware group’s dark web leak portal. This listing was published on September 6, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. It is important to note that a ransomware listing signifies that a criminal group has published the organization’s name on a site used to pressure victims into paying or to distribute stolen data, and does not confirm a breach has occurred. This listing confirms Panzer’s claim regarding Edacentrum. Panzer ransomware has claimed 21 victims in the prior 60 days, indicating a consistent mid-tier operational tempo. The group’s targeting primarily focuses on the Government & Defense, Technology, and Manufacturing sectors. Germany represents a significant portion of their geographic operational area, a trend reinforced by recent listings. Other organizations previously claimed by Panzer include SAGASTA sro, Hochschule Heilbronn Bildungscampus, Alpine Electronics Europe, and KHALED ALFAGIH ENGINEERING CONSULTANCY. Edacentrum’s listing aligns with Panzer’s sustained focus on German organizations.
Technical Analysis
The primary risk question arising for organizations operating in Panzer’s active geography relates to the currency of their credential hygiene checks against corporate domains and the review of remote-access logs. Stealer-log telemetry returned no direct hits for the domain edacentrum[.]de. However, this absence does not definitively confirm that the organization is unaffected. Credentials associated with employees may exist within feeds that were not queried, or they may have been in circulation prior to the collection of the indexed snapshot. Therefore, the lack of a hit is an input to the overall risk assessment, rather than a resolution of potential compromise. The presence of potentially compromised credentials, regardless of whether they are immediately found in stealer logs, can provide a pathway for ransomware operations. If valid corporate credentials exist in underground forums or have been harvested through infostealer malware, they can be used for initial access, reconnaissance, and lateral movement within an organization’s network. This could lead to the deployment of ransomware and subsequent data exfiltration, as is the modus operandi of groups like Panzer. Continuous monitoring of dark web forums and stealer-log feeds remains crucial.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.