RANSOMWARE VICTIMTECHNOLOGYDUPLICATE CLAIM

Woom GmbH

INCRANSOM📍 Austria (AT)📅 November 21, 2025
8
same group

Attack Intelligence

Woom GmbH was compromised in a ransomware attack attributed to INCRANSOM in November 2025. The organization, operating in the Technology sector in Austria, was added to the group's data leak site as part of an extortion campaign.

INCRANSOM operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

woom is an international manufacturer of bikes for children and teenagers with its headquarters in Klosterneuburg, outside of Vienna. The company was founded in 2013 by Christian Bezdeka and Marcus Ihlenfeld in a garage in Vienna. After a long and fruitless search for the perfect bike for their children, the two bike-loving fathers decided to take matters into their own hands and design a bike themselves: zooming in on a low weight, timeless designs, high-quality components, and child-specific geometry. In just a few years woom went from little-known brand to market leader, with woom bikes now being sold in 30 countries around the world, including Austria, Germany and Switzerland, the US and Asia.

Additional Details

Other Victims — INCRANSOM (8)

Quick Facts

CountryAustria (AT)
SectorTechnology
Attack DateNov 21, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

INCRANSOM
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.