1. Executive summary
On 2026-08-08, the Qilin ransomware group publicly listed Clausing (Germany; www.clausing-tiefbau.com) as a victim on its leak site. The posting claims data theft and extortion; no technical intrusion details, CVEs, or malware samples are provided in the source. Attribution to the Qilin group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests solely on the ransomware.live listing. Clausing is a German construction/engineering firm with no apparent direct financial-services nexus, but the activity forms part of a broader Qilin campaign targeting German and UK entities that EMEA financial institutions should monitor for supply-chain exposure.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The victim is not a financial-services entity, and the source provides no confirmed ICT third-party relationship between Clausing and regulated EMEA financial firms. If a client confirms a vendor or supply-chain relationship with Clausing, DORA Art. 28 (ICT third-party risk — general principles) and NIS2 Art. 21(2)(d) (supply chain security measures) would be triggered by that fact — but that linkage is not established in the current source material.
3. Technical analysis & attack chain
The source material is a ransomware-leak-site announcement. It contains no technical intrusion details, no CVE references, no malware sample data, no command-and-control infrastructure, and no file-system artefacts. The only confirmed facts are:
- Public listing: Qilin published Clausing as a victim on or before 2026-08-08.
- Victim profile: Clausing, a German company (domain: www.clausing-tiefbau.com), identified as a Tiefbau (civil engineering/construction) firm.
- Claimed impact: Data theft and extortion — the standard Qilin double-extortion model (exfiltration + encryption). No confirmation of encryption or specific data volumes is available in the source.
- Campaign context: Qilin has listed multiple German and UK victims in the same timeframe, including dbHMS (DE), Sitmatic (DE), GURR Abdichtungstechnik GmbH (DE), Bloom Financials (GB), and Hoc (GB). This suggests an active targeting pattern across DACH and UK regions.
Confidence caveat: All claims rest on a single source (ransomware.live indexing of the Qilin leak site). No independent corroboration of the intrusion, data theft, or encryption is available. Attribution to "Qilin" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. The leak-site claim should be treated as an allegation until corroborated by victim confirmation or technical artefacts.
No technical attack chain can be reconstructed from the available source material.
4. Mitigation & containment
P1 — Within 24 hours
- Supply-chain check: Determine whether any business unit has a vendor, subcontractor, or data-sharing relationship with Clausing (www.clausing-tiefbau.com) or any of the co-listed Qilin victims (dbHMS, Sitmatic, GURR Abdichtungstechnik, Bloom Financials, Hoc, Adpo). If a relationship exists, initiate incident review and assess whether any shared systems, data exchanges, or credentials are exposed.
- Threat-intelligence monitoring: Subscribe to Qilin leak-site monitoring via ransomware.live or equivalent feeds for ongoing victim disclosures relevant to your third-party vendor portfolio.
P2 — Within 72 hours
- Vendor outreach: If a confirmed relationship exists with Clausing or any co-listed victim, request an incident notification from the vendor including scope, data types affected, and containment status. Document the response for DORA Art. 28 / NIS2 Art. 21(2)(d) compliance evidence if applicable.
- Credential review: If any shared authentication, API keys, or service accounts exist between your organisation and the affected vendor, rotate credentials and audit access logs for anomalous activity.
P3 — Within 7 days
- Qilin TTPs briefing: Brief SOC and IR teams on Qilin's known operational patterns from prior public reporting. No TTPs are available in this source — consult CISA, FBI, or vendor Qilin/Qilin.B reports for technical detection guidance.
- Tabletop inclusion: Include a Qilin-style third-party compromise scenario in the next DORA Art. 24 resilience testing cycle, given the group's demonstrated targeting of DACH and UK entities.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Public leak-site listing by Qilin group naming victim organisation | Ransomware.live / Qilin Tor leak site | High (single-sourced) |
| Multiple German and UK organisations listed by same actor within a narrow timeframe | Ransomware.live victim feed | High (single-sourced) |
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: qilin named Clausing (DE)," https://www.ransomware.live/id/Q2xhdXNpbmdAcWlsaW4=, published 2026-08-08.
- Ransomware.live, "Ransomware: qilin named dbHMS (DE)," https://www.ransomware.live/id/ZGJITVNAcWlsaW4= (context).
- Ransomware.live, "Ransomware: qilin named Bloom Financials (GB)," https://www.ransomware.live/id/Qmxvb20gRmluYW5jaWFsc0BxaWxpbg== (context).
- Ransomware.live, "Ransomware: qilin named Sitmatic (DE)," https://www.ransomware.live/id/U2l0bWF0aWNAcWlsaW4= (context).
- Ransomware.live, "Ransomware: qilin named GURR Abdichtungstechnik GmbH (DE)," https://www.ransomware.live/id/R1VSUiBBYmRpY2h0dW5nc3RlY2huaWsgR21iSEBxaWxpbg== (context).
- Ransomware.live, "Ransomware: qilin named Hoc (GB)," https://www.ransomware.live/id/SG9jQHFpbGlu (context).
- Ransomware.live, "Ransomware: qilin named Adpo," https://www.ransomware.live/id/QWRwb0BxaWxpbg== (context).
8. Adverse Trace position
This is a low-fidelity, single-sourced leak-site disclosure with no technical artefacts. The direct risk to EMEA financial services clients is contingent on a confirmed third-party relationship with Clausing or any co-listed Qilin victim. Attribution to Qilin is unconfirmed (no MITRE ATT&CK profile in verified reference data). The campaign pattern — multiple DACH and UK victims listed in a narrow window — warrants proactive supply-chain screening but does not, on current evidence, indicate targeting of financial-services entities specifically. We will continue monitoring the Qilin leak site for additional victim disclosures and will issue a follow-up advisory if a confirmed financial-services or critical-vendor victim is identified, or if technical IOCs emerge from secondary reporting.
Published via PulseTrace — Adverse Trace threat intelligence.