RANSOMWARE VICTIMCONSTRUCTIONDUPLICATE CLAIM

Keller Polska

www.kellerpolska.pl
lynx📍 Poland (PL)📅 March 6, 2026
8
same group

Attack Intelligence

Keller Polska was compromised in a ransomware attack attributed to lynx in March 2026. The organization, operating in the Construction sector in Poland, was added to the group's data leak site as part of an extortion campaign.

lynx operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Keller Polska, operating for over 20 years, is a leader in the geotechnical market in Poland and this part of Europe. We carry out both small local projects and the largest and most important for the economy. As one of the Keller Group companies, we also have the financial capabilities, know-how, skills and global reach to handle the most demanding projects.

Additional Details

Other Victims — lynx (8)

Quick Facts

CountryPoland (PL)
SectorConstruction
Attack DateMar 6, 2026
Domainwww.kellerpolska.pl
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

lynx
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.