> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: lockbit5 named terra-petra.com (DE)
- URL: https://f4n6.co.uk/security-feed/ransomware-lockbit5-named-terra-petra-com-de/
- Published: 2026-08-18T11:09:35.000Z
- Updated: 2026-08-18T11:09:35.000Z
- Author: Jeff Davies
- Tags: #security-feed, lockbit5

## 1\. Executive summary

On 2026-08-18, the actor "lockbit5" publicly claimed a ransomware attack against Terra-Petra (terra-petra\[.\]com), an environmental engineering firm based in Germany. The claim was posted on the ransomware leak site indexed by ransomware.live. Attribution to the "lockbit5" identity is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests on a single source. No technical details, initial access vector, malware sample, or data-exfiltration evidence are available in the source material. EMEA financial services clients are unlikely to be directly impacted; the relevance is limited to any third-party or supply-chain relationship with the named victim.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The incident involves a non-financial-sector victim in Germany with no demonstrated link to an ICT third-party provider serving EMEA financial services. If a client confirms a vendor or supply-chain relationship with Terra-Petra, DORA Art. 28 (ICT third-party risk — general principles) and NIS2 Art. 21(2)(d) (supply chain security measures) would be triggered — but that relationship is not established in the available source data.

## 3\. Technical analysis & attack chain

No technical details are available in the source material. The ransomware.live posting contains only the victim name, domain, country code (DE), and a group attribution ("lockbit5"). No information is provided regarding:

- Initial access vector or exploited vulnerability
- Malware payload, variant, or capabilities
- Persistence mechanism
- Privilege escalation technique
- Command-and-control infrastructure
- Lateral movement
- Data access or exfiltration volume/content
- Ransom demand or payment instructions
- Encryption scope or impact

**Attribution caveat:** The actor "lockbit5" has no MITRE ATT&CK profile in the verified reference data. Attribution is unconfirmed. The name may indicate a successor or rebrand of the LockBit operation, but this is speculative and not supported by the source material. The claim is single-sourced (ransomware.live); verify before enforcement.

**Victim context:** Terra-Petra is described as an environmental engineering firm specialising in contaminated soil and groundwater consulting. The firm is based in Germany. No financial services connection is indicated.

## 4\. Mitigation & containment

### P1 — Within 24h

- Determine whether your organisation has a direct or indirect vendor/supplier relationship with Terra-Petra (terra-petra\[.\]com). Check procurement records, vendor management databases, and third-party risk registers.
- If a relationship exists: assess what data, systems, or services Terra-Petra has access to and whether any integration points (APIs, shared credentials, file transfers) require suspension pending confirmation of the breach scope.

### P2 — Within 72h

- If a third-party relationship is confirmed, initiate incident review under your ICT third-party risk framework. Request a breach notification from Terra-Petra including scope, data types affected, and containment status.
- Block the victim domain (terra-petra\[.\]com) at web proxy and email gateway if there is concern about attacker-controlled infrastructure using the compromised domain.

### P3 — Within 7 days

- No patch or configuration remediation applies — this is a third-party incident, not a product vulnerability.
- If no relationship exists, no further action is required beyond logging this advisory for situational awareness.

## 5\. Indicators of compromise

No indicators of compromise available in the source material. The posting does not include hashes, IP addresses, C2 domains, file paths, or other atomic indicators. No leak screenshot content or DNS records were provided in the source data.

**Behavioural indicators:** None available — the source provides no observable behaviours (process activity, network patterns, authentication anomalies, or device registrations).

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- Ransomware.live — "Victim: terra-petra.com – lockbit5" — https://www.ransomware.live/id/dGVycmEtcGV0cmEuY29tQGxvY2tiaXQ1 — 2026-08-18

## 8\. Adverse Trace position

This is a low-confidence, single-sourced ransomware claim with no technical detail and unconfirmed actor attribution. The victim is a German environmental engineering firm with no demonstrated link to EMEA financial services. Severity is low for direct client impact but moderate for supply-chain exposure if a client vendor relationship exists. We will monitor for corroborating reporting, leak-site data releases, and any emergence of IOCs or malware samples associated with the "lockbit5" identity. Clients should treat the attribution as unconfirmed and not action it beyond third-party relationship checks.

---

[Read the original source →](https://www.ransomware.live/id/dGVycmEtcGV0cmEuY29tQGxvY2tiaXQ1?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*