Ransomware Group intelligence
Incransom
ActiveTrack Incransom with 1037 published victims and 7 known leak locations in a single intelligence view.
Overview
Incransom is tracked by Breach House as a ransomware group with 1037 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 34 26.8%
- Pending 92 72.4%
- Deleted 1 0.8%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 7 | Onion service | Up checked 21m ago | incbacg6bfwtrlzwdbqc55gsfl763s3twdtwhp27dzuik6s6rwdcityd.onion |
| Leak location 6 | Onion service | Down checked 21m ago | incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion |
| Leak location 2 | Onion service | Down checked 21m ago | incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd.onion |
| Leak location 5 | Web location | Down checked 22m ago | incapt.su |
| Leak location 1 | Onion service | Down checked 22m ago | incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion |
| Leak location 4 | Web location | Down checked 22m ago | incapt.blog |
| Leak location 3 | Web location | Down checked 22m ago | incbackend.top |
Top Activity Sectors (18)
- Communication / Marketing 173
- Healthcare / Pharma 113
- Finance / Legal / Insurance 111
- Services 76
- Manufacturing / Engineering 71
- Education 57
- Construction / Real Estate 54
- Not identified 54
- Public Sector 44
- IT 39
- Retail / E-commerce 27
- NGOs / Associations 24
- Transportation / Travel / Logistics 23
- Energy 21
- Hospitality / Food & Beverage / Tourism 16
- Agriculture / Food 14
- Telecommunications 11
- null 1
Typical Attacks (35)
▼How Incransom typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via INC Ransom, INC Ransomware.
-
T1588.002 Tool Resource Development
What they do: INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: INC Ransom has used compromised valid accounts for access to victim environments.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566 Phishing Initial Access
What they do: INC Ransom has used phishing to gain initial access.
What that means: Adversaries may send phishing messages to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: INC Ransom has used WMIC to deploy ransomware.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.003 Windows Command Shell Execution
What they do: INC Ransom has used `cmd.exe` to launch malicious payloads.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: INC Ransom has uninstalled tools from compromised endpoints after use.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1046 Network Service Discovery Discovery
What they do: INC Ransom has used NETSCAN.EXE for internal reconnaissance.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1049 System Network Connections Discovery Discovery
What they do: INC Ransom has used RDP to test network connections.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: INC Ransom has enumerated domain groups on targeted hosts.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1083 File and Directory Discovery Discovery
What they do: INC Ransomware can receive command line arguments to encrypt specific files and directories.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.002 Domain Account Discovery
What they do: INC Ransom has scanned for domain admin accounts in compromised environments.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1120 Peripheral Device Discovery Discovery
What they do: INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: INC Ransom has used Internet Explorer to view folders on other systems.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1652 Device Driver Discovery Discovery
What they do: INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: INC Ransomware can discover and mount hidden drives to encrypt them.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: INC Ransom has used RDP to move laterally.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1074 Data Staged Collection
What they do: INC Ransom has staged data on compromised hosts prior to exfiltration.
What that means: Adversaries may stage collected data in a central location or directory prior to Exfiltration.
-
T1560.001 Archive via Utility Collection
What they do: INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1071 Application Layer Protocol Command and Control
What they do: INC Ransom has used valid accounts over RDP to connect to targeted systems.
What that means: Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: INC Ransom has used AnyDesk and PuTTY on compromised systems.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1537 Transfer Data to Cloud Account Exfiltration
What they do: INC Ransom has used Megasync to exfiltrate data to the cloud.
What that means: Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
-
T1486 Data Encrypted for Impact Impact
What they do: INC Ransom has used INC Ransomware to encrypt victim's data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: INC Ransomware can issue a command to kill a process on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: INC Ransomware can delete volume shadow copy backups from victim machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: INC Ransomware has the ability to change the background wallpaper image to display the ransom note.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1657 Financial Theft Impact
What they do: INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (11)
▼Software Incransom has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (1037)
Search, filter and paginate the victim timeline for Incransom. Showing 1–100 of 1037.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | jms building corporation id32736 View details | United States | Construction / Real Estate | pending | ||
|
jms Building Corporation operates within the Construction and Real Estate sector, with headquarters and activities situated in the United States. The entity provides building management, property development support, or related construction services, serving clients and stakeholders across the sector. According to the threat-intelligence index, jms Building Corporation is listed as a ransomware victim associated with threat actor incransom. This listing reflects the cybersecurity event documented within the index and provides context for monitoring related threats in the Construction and Real Estate domain. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per strict factual reporting guidelines. |
||||||
| Ransomware | jms building corporation id32736 View details | United States | Construction / Real Estate | pending | ||
|
JMS Building Construction is a full service Insurance Restoration construction company that handles every step of the Insurance Restoration process, from dealing with your insurance company to restoring your home's integrity WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information! |
||||||
| Ransomware | cullottalaw.com id32723 View details | United States | Finance / Legal / Insurance | pending | ||
|
cullottalaw.com operates within the United States in the Finance, Legal, and Insurance sectors, providing specialized services aligned with regulated and high-value industry requirements. As a ransomware victim entry in the threat-intelligence index, the entity is documented under the incransom threat actor classification. This listing type indicates a cybersecurity incident involving ransomware activity, without disclosing confirmed technical details, data exfiltration specifics, or financial impact. The catalog entry serves threat-intelligence purposes by contextualizing the entity within its sector, geographic location, and associated malicious actor for analytical and defensive use. Neutral documentation ensures transparency while adhering to strict non-disclosure of unverified incident particulars. |
||||||
| Ransomware | cullottalaw.com id32723 View details | United States | Finance / Legal / Insurance | pending | ||
|
Cullotta Bravo Law Group is a personal injury law firm based in Aurora, IL, with over 35 years of experience in various legal areas including personal injury, nursing home abuse, and workers compensation. |
||||||
| Ransomware | https://mediengruppethiel.de/ id32713 View details | Germany | Services | pending | ||
|
mediengruppethiel.de is a German company operating within the Services sector, providing media and related professional services based in Germany. The entity is formally listed within this threat-intelligence index under the designation of ransomware victim. Its inclusion is specifically associated with the threat actor incransom, indicating a cybersecurity event where this organization was impacted by ransomware activity. This catalog entry serves to document the relationship between the affected entity, its operational context, and the identified threat actor for threat-intelligence analysis and awareness purposes. |
||||||
| Ransomware | https://mediengruppethiel.de/ id32713 View details | Germany | Services | pending | ||
|
Die Mediengruppe Thiel aus Ludwigsfelde ist Ihr verlässlicher Druck- und Werbepartner, wenn es um individuelle Lösungen für innen und außen geht. Ob eindrucksvolle Printprodukte, maßgeschneiderte Werbetechnik oder professionelle Geschäftsausstattung – bei uns erhalten Sie alles aus einer Hand. Dank unseres breiten Leistungsspektrums sparen Sie sich Wege, Schnittstellen und Zeit – und können sich ganz auf Ihr Kerngeschäft konzentrieren. Unser engagiertes Team aus Ideengebern, Technik-Profis und Gestaltern begleitet Sie dabei von der ersten Idee bis zur fertigen Umsetzung. |
||||||
| Ransomware | Wellness Partners network(combined revenue) id32648 View details | United States | Services | pending | ||
|
Wellness Partners network(combined revenue) is a Services-sector entity located in the United States, operating within a wellness and partnership service context. The listing type identifies it as a ransomware victim within the threat-intelligence index. Associated with the threat actor incransom, this entry documents the entity's classification without revealing unverified incident details such as stolen data, records compromised, ransom demands, or confirmed breach specifics. The catalog description remains neutral and authoritative, focused on entity profile, sector, location, listing classification, and the associated threat actor for analytical and indexing purposes. |
||||||
| Ransomware | Wellness Partners network(combined revenue) id32648 View details | United States | Services | pending | ||
|
Headquartered in Clinton, New York Community Wellness Partners is a faith based non-profit organization that provides healthcare, housing and community services. They also have 24/7 skilled-nursing care to older adults who require residential medical care and support services. |
||||||
| Ransomware | myglobal.com id32460 View details | Malaysia | Services | leaked | ||
|
myglobal.com operates within the Services sector and is associated with the country Malaysia. The entity represents a services organization referenced within the threat-intelligence index under the classification ransomware victim. Its inclusion reflects threat-intelligence analysis linking the entity to the incransom threat actor profile. This listing provides neutral catalog context for cybersecurity professionals monitoring service-sector exposure and ransomware-related incidents across regional threat landscapes. No breach details, data claims, or confirmed incident specifics are included in this description. |
||||||
| Ransomware | myglobal.com id32460 View details | Malaysia | Services | leaked | ||
|
My Global Services Sdn Bhd is the first authorized distributor of OLED LiFi in Malaysia, specializing in OLED LiFi technology, mechanical and electrical engineering, as well as civil and construction services. The company provides solutions for scientists and research workers, offering sales and support for scientific equipment. Their services include civil and structural engineering, ensuring a comprehensive approach to their clients' needs. With a focus on innovative lighting solutions, they aim to enhance the capabilities of their clients across various sectors. Employees: 10 Revenue: $5 Million Industry: Architecture, Engineering & Design Phone Number: +60 358922797 |
||||||
| Ransomware | Asfaltos y Pavimentos S.A. (Asfalpasa) id32421 View details | Spain | Agriculture / Food | leaked | ||
|
Asfaltos y Pavimentos S.A., commonly known as Asfalpasa, operates within the agriculture and food sector in Spain, providing asphalt and paving materials essential for infrastructure and related industrial applications. The entity is formally listed within the threat-intelligence index under the designation of ransomware victim, with the associated threat actor or source identified as incransom. This classification reflects the cybersecurity event documented in the index, without elaborating on unverified technical details such as data exfiltration scope, ransom demands, or internal incident specifics. The catalog entry serves to contextualize the organization's exposure within the landscape of cyber threats targeting Spanish agricultural enterprises. Asfaltos y Pavimentos S.A. (Asfalpasa) was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | Asfaltos y Pavimentos S.A. (Asfalpasa) id32421 View details | Spain | Agriculture / Food | leaked | ||
|
Empresa dedicada a la fabricación, transporte y extendido de mezclas asfálticas así como todo tipo de servicios relacionados con la construcción y mantenimiento de carreteras, vias públicas y privadas. Desde sus comienzos en 1982 Asfaltos y Pavimentos (ASFALPASA) se basa en un equipo humano especializado y experimentado en la actividad que posteriormente llevaría a cabo la empresa. Dicha experiencia aporta a la empresa un rápido crecimiento y un alto grado de especialización y competitividad que hace de Asfalpasa una de las empresas más conocidas de su sector. |
||||||
| Ransomware | Westfield Public School District id32422 View details | United States | Education | pending | ||
|
Westfield Public School District is a public education institution operating within the United States, providing K-12 academic programs, student support services, administrative operations, and community-focused school resources for its student and staff population. As an education sector entity, it represents a critical infrastructure category frequently targeted by cyber threats, including ransomware campaigns aimed at disrupting instructional continuity and operational systems. This listing identifies Westfield Public School District as a ransomware victim associated with the threat actor incransom. The catalog entry reflects threat-intelligence indexing without confirming specific breach details, data exposure, or operational impact. It serves to document the entity's exposure profile within the broader cybersecurity landscape for education sector organizations. |
||||||
| Ransomware | Westfield Public School District id32422 View details | United States | Education | pending | ||
|
Westfield Public Schools is dedicated to educating all students to reach their highest potential as engaged citizens who value diversity. The district focuses on inclusivity, community engagement, wellness, and comprehensive financial planning to enhance the educational experience. Their strategic plan outlines long-term goals and strategies to align resources with the needs of students and staff. The intended clients include students, families, and the broader community in Westfield, NJ. |
||||||
| Ransomware | Trucka id32423 View details | Mexico | Transportation / Travel / Logistics | pending | ||
|
Trucka operates within the Transportation, Travel, and Logistics sector, with operational base and market presence associated with Mexico. The entity functions as a commercial organization serving transportation and logistics services, maintaining industry relevance within supply chain and mobility networks. It is formally cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor incransom. This listing reflects the entity's classification within cybersecurity intelligence records without disclosing unverified incident details. The association identifies Trucka as a target category under incransom activity within the specified geographic and sectoral context. |
||||||
| Ransomware | Trucka id32423 View details | Mexico | Transportation / Travel / Logistics | pending | ||
|
Trucka is a transportation and logistics company that helps businesses move goods across different regions. They handle everything from local deliveries to long-distance shipping, working with companies of all sizes. Their trucks cover major routes, making sure packages and freight get where they need to go safely and on time. With a team of experienced drivers and a solid network of shipping routes, Trucka makes moving cargo simple and reliable. |
||||||
| Ransomware | Policlinico Triestino id32424 View details | Italy | Healthcare / Pharma | pending | ||
|
Policlinico Triestino operates within the Healthcare and Medicine sector, providing clinical and medical services to patients and regional communities. As a prominent healthcare entity in the IT country context, it maintains critical operational infrastructure supporting diagnosis, treatment, and patient care across its services. This listing identifies Policlinico Triestino within the ransomware victim category of the threat-intelligence index, specifically linked to the incransom threat actor. The record documents the association neutrally without disclosing unverified incident details such as data stolen, records impacted, ransom demands, or confirmed breach specifics. This catalog entry serves to inform stakeholders of the entity's exposure profile within cyber threat intelligence frameworks. |
||||||
| Ransomware | Policlinico Triestino id32424 View details | Italy | Healthcare / Pharma | pending | ||
|
Policlinico Triestino S.p.A. is a private healthcare network based in Trieste, Italy, that operates hospitals, nursing homes, and outpatient clinics. |
||||||
| Ransomware | Multiver Ltée id32425 View details | Canada | — | pending | ||
|
Multiver Ltée is a Canadian enterprise organization operating within the technology and business services sector, providing digital solutions and operational support to clients. As a ransomware victim listed in this threat-intelligence index, Multiver Ltée is documented alongside the incransom threat actor and source, with country attribution set to Canada. The listing type identifies the entity as directly affected by ransomware activity linked to incransom, presented neutrally without speculation regarding data theft, ransom demands, or confirmed breach details. This entry serves as a factual catalog record for threat researchers and security professionals monitoring incident relationships across the affected organization and associated actor. |
||||||
| Ransomware | Multiver Ltée id32425 View details | Canada | — | pending | ||
|
Multiver Ltée specializes in the manufacturing of glass products, offering a range of solutions from sealed to tempered and shaped glass. With over 50 years of experience, the company is renowned for its craftsmanship and commitment to timely delivery. They have successfully completed various architectural projects, showcasing both subtle and bold designs. Their intended clients include those looking to enhance their construction with high-quality glass features. |
||||||
| Ransomware | Metales Panamericanos id32426 View details | Panama | Manufacturing / Engineering | pending | ||
|
Metales Panamericanos is a company operating within the manufacturing and engineering sectors, headquartered in Panama. Its role within the threat-intelligence index is defined as a ransomware victim, with the associated threat actor and source identified as incransom. The listing reflects observed cybersecurity event correlation rather than confirmed breach details, emphasizing the entity's exposure within industrial supply chain contexts. This catalog entry supports threat-mapping efforts for sectors and regions vulnerable to disruptive cyber activity. Metales Panamericanos was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | Metales Panamericanos id32426 View details | Panama | Manufacturing / Engineering | pending | ||
|
English Metales Panamericanos, previously known as ACERO PANAMA, is the main construction & steel supplier to the Construction industry in Panama, initially focus in steel materials, now our new mission is extended to different constructions systems, Electrical Solutions, Equipment & Devices, zing ceilings, strollers, metal wires, windows structures, gypsum, among others. Spanish Metales Panamericanos S.A. (METALPAN), previamente conocida como ACERO PANAMA, es una dinmica y exitosa sociedad 100% panamea que se constituyo como METALPAN en el ao 1991, y que ha sabido transformarse y crecer con firmeza para responder de manera rpida y eficaz a las exigencias del clientes con altos niveles de competitividad presentes en el mercado nacional. |
||||||
| Ransomware | specialtytextile.com id32412 View details | United States | Manufacturing / Engineering | pending | ||
|
specialtytextile.com operates within the United States manufacturing and engineering sector, specializing in specialty textile solutions and related offerings. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with incransom identified as the associated threat actor or source. This classification reflects the cybersecurity context in which the organization was documented, without disclosing unverified incident details such as data exfiltration scope, ransom terms, or specific compromise mechanisms. The entry serves to inform stakeholders of the entity's exposure profile within the indexed threat landscape. specialtytextile.com was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | specialtytextile.com id32412 View details | United States | Manufacturing / Engineering | pending | ||
|
Specialty Textile Services is a U.S. textile services company founded in 1996, specializing in linen rental and processing for the hospitality industry. Headquartered in Phoenix, Arizona, with a branch in San Diego, California, the company employs between 201 and 500 people. Serving mid-to-high-end restaurants, hotels, and other hospitality providers, Specialty Textile Services offers flexible rental programs covering a full line of linens, kitchen textiles, uniforms, and dust control products — all delivered clean and ready for use. Key features include: flexible pickup and delivery schedules, including multiple weekly service visits; all-inclusive service pricing with no upfront investment required from customers; an in-house commercial laundry facility operating 7 days a week, 365 days a year, with rapid emergency response available for special requests. |
||||||
| Ransomware | New Century Ophthalmology Group id32339 View details | United States | Healthcare / Pharma | pending | ||
|
New Century Ophthalmology Group operates within the healthcare and medicine sector, providing ophthalmic services and patient care in the United States. As a healthcare organization, it handles sensitive patient information and clinical workflows, making it a potential target for cyber threats. This entity is formally listed within the threat-intelligence index as a ransomware victim associated with the threat actor incransom. The listing reflects the observed relationship between the organization and the identified threat actor without disclosing unverified incident details. This catalog entry supports threat-aware monitoring and context for cybersecurity professionals tracking healthcare sector exposures. |
||||||
| Ransomware | New Century Ophthalmology Group id32339 View details | United States | Healthcare / Pharma | pending | ||
|
New Century Ophthalmology is a leading ophthalmology practice located in Raleigh and Oxford, NC, specializing in advanced eye care services including cataract surgery, glaucoma treatment, and oculoplastic procedures. The practice is dedicated to providing personalized, high-quality care with a focus on patient well-being and innovative treatment options. Their team of fellowship-trained specialists utilizes state-of-the-art technology to ensure optimal outcomes for a variety of eye conditions. New Century Ophthalmology serves a diverse clientele seeking comprehensive eye health solutions and aesthetic enhancements |
||||||
| Ransomware | zummocorp.com id32331 View details | United States | IT | pending | ||
|
zummocorp.com operates within the IT sector and is situated in the United States. The entity represents a business organization that was identified within a threat-intelligence index as a ransomware victim linked to the incransom threat actor. This listing type categorizes the entity based on its documented association with a cyber threat campaign targeting IT infrastructure. The entry provides neutral context for cybersecurity professionals monitoring ransomware incidents across sectors and geographic regions. No specific incident details such as data stolen, ransom demands, or breach confirmations are included per strict factual reporting guidelines. |
||||||
| Ransomware | zummocorp.com id32331 View details | United States | IT | pending | ||
|
Zummo is a global incumbent in the design, manufacture and commercialization of automatic fresh fruit juice extraction machines, mainly aimed at the food service and food retail segments. |
||||||
| Ransomware | www.lichtvision.com id32332 View details | United Kingdom | Manufacturing / Engineering | pending | ||
|
www.lichtvision.com operates within the Manufacturing and Engineering sector, based in the United Kingdom. The entity provides specialized technical and operational services relevant to industrial workflows and engineering solutions. This listing type identifies www.lichtvision.com as a ransomware victim within the threat-intelligence index. The associated threat actor and source for this record is incransom. The entry reflects the organization's inclusion in the ransomware victim category linked to this specific threat actor, presented neutrally for catalog purposes. |
||||||
| Ransomware | www.lichtvision.com id32332 View details | United Kingdom | Manufacturing / Engineering | pending | ||
|
Lichtvision specializes in innovative lighting design, focusing on architectural spaces through the use of daylight, artificial light, and immersive media technologies. With a team of 40 designers, architects, and engineers, they provide sustainable and aesthetically pleasing lighting solutions for a variety of projects, including museums, offices, and retail spaces. Established in 1997, Lichtvision has a global presence with studios in major cities and emphasizes a holistic approach to lighting that enhances the quality of life. Their work is characterized by a blend of creativity, technical expertise, and a commitment to ecological sustainability. |
||||||
| Ransomware | www.renorefractories.com id32333 View details | United States | Manufacturing / Engineering | pending | ||
|
www.renorefractories.com operates within the United States manufacturing and engineering sector, providing specialized repair and technical services aligned with industrial operations. The entity is cataloged specifically as a ransomware victim within the threat-intelligence index, linked to the incransom threat actor or source identifier. This listing type indicates documented exposure or impact related to malicious cyber activity targeting organizations in this sector. The description remains neutral and avoids speculation regarding data loss, ransom demands, or confirmed breach details, focusing solely on the entity's classification and associated threat context for analytical reference. |
||||||
| Ransomware | www.renorefractories.com id32333 View details | United States | Manufacturing / Engineering | pending | ||
|
RENO Refractories, Inc. specializes in the manufacturing of refractory products and services for various industrial applications, including aluminum, iron and steel, cement and lime, foundries, mini mills, and hydrocarbon processing. With over 35 years of experience, the company is committed to innovation and quality, providing advanced research and development, technical support, and installation services. Their product offerings include a full range of monolithic products and the revolutionary ElectroCast product line. RENO aims to optimize the profits and safety of their clients by delivering superior refractory technology across North America. |
||||||
| Ransomware | cimbsecurities.com id32334 View details | Malaysia | Finance / Legal / Insurance | — | ||
|
cimbsecurities.com operates within the Finance, Legal, and Insurance sectors and is associated with the country Malaysia. The entity is documented in this threat-intelligence index under the listing type ransomware victim, with incransom identified as the associated threat actor or source. This record provides neutral context regarding the cybersecurity event connected to the organization without disclosing unverified incident details such as data stolen, ransom demands, or breach confirmation. The inclusion reflects the index's role in mapping real-world entities to active cyber threats for risk assessment and intelligence monitoring purposes. |
||||||
| Ransomware | cimbsecurities.com id32334 View details | Malaysia | Finance / Legal / Insurance | — | ||
|
Bank |
||||||
| Ransomware | wittmann id32260 View details | Mexico | Manufacturing / Engineering | — | ||
|
Wittmann operates within the Manufacturing and Engineering sector and is associated with the country Mexico. As a ransomware victim indexed in this threat-intelligence catalog, the entity is documented to illustrate exposure patterns within industrial and engineering supply chains. The listing explicitly associates wittmann with the threat actor incransom, reflecting its inclusion as a ransomware victim case. This entry provides neutral context on the entity's sector, geographic origin, and its classification within the ransomware incident framework. No specific breach details, data loss metrics, or confirmed incident specifics are included, preserving factual integrity and avoiding speculation regarding the nature or scope of the threat. |
||||||
| Ransomware | wittmann id32260 View details | Mexico | Manufacturing / Engineering | — | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation.NDA files |
||||||
| Ransomware | Oilquip Inc id32253 View details | United States | Services | — | ||
|
Oilquip Inc is a United States-based company operating within the Services sector, providing professional and technology-driven offerings to clients. As part of the threat-intelligence catalog, Oilquip Inc is formally listed as a ransomware victim associated with the threat actor incransom. This designation reflects its inclusion in the index due to its connection with this specific cyber threat actor within its operational context. The entry documents the entity's status without disclosing unverified incident details, maintaining neutrality and adherence to factual reporting standards for cybersecurity intelligence. |
||||||
| Ransomware | Oilquip Inc id32253 View details | United States | Services | — | ||
|
Oilquip Inc, established in 1960, is a comprehensive fluid power distributor that specializes in hydraulics, pneumatics, oil conditioning, and system integration. The company is dedicated to providing innovative electro-hydraulic and electro-mechanical solutions while exceeding customer expectations. Their services include design and engineering, fluid conditioning, power generation, and repairs and upgrades, catering to a diverse range of clients. Oilquip prides itself on its customer-focused approach, flexibility, and commitment to excellence in all aspects of its operations. |
||||||
| Ransomware | BENCIVIL id32204 View details | United States | IT | — | ||
|
BENCIVIL is an entity operating within the US IT sector, cataloged as a ransomware victim within a threat-intelligence index. Its classification reflects its role as an organization impacted by malicious cyber activity targeting information technology infrastructure. The listing explicitly associates BENCIVIL with the threat actor incransom, providing context for its security posture and incident classification. This entry serves threat analysts and cybersecurity professionals seeking structured intelligence on affected entities and linked threat campaigns. The description remains neutral and factual, documenting the entity's designation without extrapolating unverified incident details. |
||||||
| Ransomware | BENCIVIL id32204 View details | United States | IT | — | ||
|
Benchmark Civil Engineering Services, Inc. is a civil engineering firm based in Allentown, PA, specializing in civil engineering, traffic studies, forensic engineering, and land surveying. The company serves municipalities and clients in the Lehigh Valley and surrounding areas, providing expert services in traffic and transportation engineering, land development, and construction engineering. With a focus on professionalism and integrity, Benchmark is committed to guiding clients through the design, approval, and construction processes. Their highly trained staff utilizes state-of-the-art technology to ensure project success and compliance with regulations. |
||||||
| Ransomware | Rohloff Group id32198 View details | South Africa | Services | — | ||
|
Rohloff Group operates within the Services sector and is located in South Africa (country code ZA). The entity functions as a commercial organization providing service-oriented offerings, though specific operational details beyond its sector classification are not disclosed in public threat-intelligence records. This listing type identifies Rohloff Group as a ransomware victim associated with the incransom threat actor or source. The catalog entry reflects the entity's inclusion in the threat-intelligence index based on this association. No additional incident specifics, such as confirmed breach details, data exfiltration claims, or ransom terms, are provided to maintain factual neutrality and avoid speculation. |
||||||
| Ransomware | Rohloff Group id32198 View details | South Africa | Services | — | ||
|
KFC Rohloff Group franchise partner Total leak: 536 GB, 103,196 Files, 30,805 Folders Data: Employees personal , Loan applications, Employees banking details, ID's, Bank account statements, Employees ACKNOWLEDGEMENT OF DEBT, RESULT OF THE DISCIPLINARY HEARING, Financial documentation for royalties, Food Cost Reconciliation and a lot of other documentation. Data type: Confidential Full publication coming soon. |
||||||
| Ransomware | Ruby Seven Studios id32193 View details | United States | IT | — | ||
|
Ruby Seven Studios is an organization operating within the IT sector based in the United States. The entity functions as a technology studio or service provider, though specific operational details remain limited within public threat intelligence records. It has been formally cataloged as a ransomware victim linked to the incransom threat actor group. This listing type indicates its association with a cybersecurity incident involving ransomware activity, contributing contextual data to threat-intelligence indexing efforts. The description maintains neutrality regarding unverified incident specifics, focusing solely on the documented relationship between the entity, its sector, location, and the identified threat actor. |
||||||
| Ransomware | Ruby Seven Studios id32193 View details | United States | IT | — | ||
|
Ruby Seven Studios Inc. https://www.rubyseven.com/ Total leak: 114 GB (123,463,823,360 bytes), 133,851 Files, 49,357 Folders. Data: Source code, Games Rules, Game assets, Game math, GDD, IGT, Analytics report Finance doc's, Royalty Reports, Tax invoice, Inventions Agreement - Employee intellectual property assignment, non competition and confidentiality agreement Personal ID/Passport, Share holders list. Data type: Confifential Partners: IGT (International Game Technology), Konami Gaming, Wazdan, Bluberi Gaming, CHAYOWO TECHNOLOGY, Everi & Aristocrat Bally's Corporation, Delaware North Gaming, Pechanga Resort & Casino, Mystic Lake Casino Hotel, Affinity Interactive, Choctaw Casinos & Resorts. Full publication coming soon. |
||||||
| Ransomware | FFKR Architects id32078 View details | United States | Manufacturing / Engineering | pending | ||
|
FFKR Architects is a company operating within the United States, specializing in Manufacturing and Engineering sectors. The organization provides professional architectural and engineering consultancy services tailored to industrial and technical project requirements. FFKR Architects has been formally listed as a ransomware victim within the threat-intelligence index, with the associated threat actor or source identified as incransom. This listing reflects the entity's inclusion in cyber threat monitoring records tied to this specific ransomware-related activity. The description remains neutral and factual regarding the victim classification and associated actor. |
||||||
| Ransomware | FFKR Architects id32078 View details | United States | Manufacturing / Engineering | pending | ||
|
FFKR Architects is a leading architecture and interior design firm based in Utah, with additional offices in Arizona and Idaho. They offer a wide range of services including architecture, landscape architecture, interior design, and environmental graphic design. The firm is known for its design excellence and commitment to environmental leadership, serving various sectors such as healthcare, education, hospitality, and commercial projects. With a team of over 170 professionals, FFKR empowers clients through innovative visualization techniques, ensuring informed decision-making. |
||||||
| Ransomware | el-group id32011 View details | Switzerland | null | — | ||
|
El-group is cataloged as a ransomware victim entity within the threat-intelligence index. Its operational context is associated with the country CH, though the specific sector remains unclassified in available data. The entity represents an organization impacted by cyber activity tied to the incransom threat actor, contributing contextual detail for analysts tracking ransomware-related incidents and associated actors. This listing type identifies el-group specifically as a ransomware victim linked to incransom. The description maintains neutrality regarding incident specifics, avoiding assumptions about data stolen, operational impact, or confirmed breach details. El-group serves as a reference point in the index for understanding ransomware victim profiles and their connections to identified threat actors. |
||||||
| Ransomware | el-group id32011 View details | Switzerland | null | — | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
||||||
| Ransomware | BANGKOKCABLE id31891 View details | Thailand | — | — | ||
|
About Bangkok Cable Bangkok Cable is Thailand's leading manufacturer of electric wires and cables, boasting over five decades of sustainable growth. The company is committed to connecting people with power and driving economic development through innovative manufacturing technologies. With a production capacity of 30,000 metric tons per year for copper and 15,000 metric tons for aluminum cables, Bangkok Cable adheres to high-quality standards and sustainable practices. Their products serve a wide range of clients, contributing to the country's development and enhancing the quality of life through reliable electrical power. |
||||||
| Ransomware | UNIPLASTICS.COM id31892 View details | United States | — | — | ||
|
Universal Plastics Inc. is a family-owned commercial specialty subcontractor with over 50 years of experience, specializing in custom wall panel systems, wall protection, and high-impact wall coverings. They serve a diverse clientele, including commercial projects such as airports and medical facilities, providing innovative solutions with materials like FRP, stainless steel, and plastic laminates. As a master distributor for Marlite in Northern California, they also offer a wide range of products including solid surfaces and decorative wall panels. Their commitment to quality and customer service makes them a leader in the industry. |
||||||
| Ransomware | CDGARVINLAW id31893 View details | United States | — | — | ||
|
CHRISTOPHER D. GARVIN (Docket #2352300) is a Wood-Ridge attorney admitted to New York State in 1990 and registered with the Office of Court Administration (OCA) of the New York State Unified Court System. Employer - CHRISTOPHER D. GARVIN, ESQ. COUNSEL AT LAW. The attorney graduated from SETON HALL UNIVERSITY. The registered office is located at 268 Valley Blvd, Wood Ridge, NJ 07075-1202, contact telephone: (201) 804-7681. Current lawyer status: registered. |
||||||
| Ransomware | EXEL id31894 View details | Canada | — | pending | ||
|
Exel Systems Inc. specializes in providing high-quality custom heating, ventilation, and air conditioning (HVAC) and energy recovery products. Established in 1993, the company serves the institutional, commercial, and industrial markets, collaborating with building owners, consulting engineers, and contractors to deliver innovative and energy-efficient solutions. Their extensive product range and expertise enable them to handle complex projects tailored to specific client needs. Exel Systems encourages clients to explore their website for new products and application information to enhance building sustainability. |
||||||
| Ransomware | SpearFin Ltd id31824 View details | Mauritius | — | — | ||
|
SpearFin Ltd https://spearfin.net SpearFin offers a wide range of services including fund administration, corporate services, compliance support, and investor relations. Assets Under Administration US$10 billion. The leak occurred on June 26, 2026. Total leak: 416 GB Leak included: NDA, Correspondence Client, KYC - Passports, Certificates, Investing documents, Share Registry and Holders, Anti-Money Laundering (AML) audit, Agreements, Application forms, Bank Statements, Bank Payrolls, Loans Documents, Certificates of GBC (Global Business Company), Register of Directors and many other financial documents. Clients: YuMee Seven Six, BAMBOO BAY PRIVATE LIMITED, Asio Global Fund, 3B Capital, Abans Group, Amicorp Capital, Apex Fund Services Ltd, Pangaea Fund Limited, AL Farah Overseas Limited, Zinnia Group, AMG Services Ltd, NEO SEMI SG PTE. LTD, MIC ELECTRONICS LIMITED, Zenbridge Capital Pvt. Ltd., Zinnia Investment Advisers Pvt Ltd, Onpoint Ventures Limited, Wilson Group, Blue River, Capital Advisors Private Limited, Zenbridge Capital Pvt Ltd, Topland Group Holdings, Africa Opportunities Fund, Appollo Fund Limited and many other... Type of information: Confidential Full publication coming soon... |
||||||
| Ransomware | ssf-int.com ssf-ing.de id31825 View details | Germany | — | — | ||
|
SSF International GmbH is an engineering firm headquartered in Munich, Germany. A subsidiary of SSF Ingenieure AG, the company provides comprehensive engineering services in project management, supervision, consultancy, design, quality management, and special construction design worldwide. It specializes in railways, high-speed railway lines, metro and light rail, Maglev lines, and large infrastructure projects, including bridges and railway stations. The company serves international clients across various stages of project development, from early studies and design to construction, commissioning, operation, and maintenance. Its service portfolio includes BIM and GIS solutions, environmental protection, and specialized solutions for acoustic and vibration control. |
||||||
| Ransomware | nyklawfirm.com nyk.ae id31826 View details | United Arab Emirates | — | — | ||
|
/ |
||||||
| Ransomware | Foresee Pharmaceuticals id31822 View details | Taiwan, Province of China | — | pending | ||
|
Foresee Pharmaceuticals Co., Ltd. https://www.foreseepharma.com Total leak: 1,2TB Leak includes: Drug Master File, ASMF, FDA/EMA, R&D, Financial statements, Clinical study reports and other confidential information. Projects: CAMCEVI, SIF, Casppian, NCE, Aderamastat, Linvemastat, FP-045, FP-016, FP-018, FP-014... Partners: Accord BioPharma, Intas Pharmaceuticals, Primevera Therapeutics, Accord Healthcare... Type of information: Confidential |
||||||
| Ransomware | SD Associates Sdn Bhd id31810 View details | Malaysia | — | — | ||
|
SD Associates (SDA) is a globally expanding company that prides itself in providing quality service to every client. We provide comprehensive professional project management and engineering consultancy services in diverse market segments. Our multi-disciplinary teams consisting of experienced Project Managers, Professional Engineers, Architects, Quantity surveyors, and Technical Support Managers. We are an ISO 9001, ISO 45001, and ISO 14001 certified WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information! |
||||||
| Ransomware | Third Coast Bancshares id31811 View details | United States | — | — | ||
|
While Third Coast Bancshares (NASDAQ:TCBX) shares continue to rise rapidly and reach new highs, its leadership is concealing one of the largest data breaches in the history of the U.S. financial sector. This situation raises serious questions about the company’s conduct. In the near future, we intend to publish a comprehensive analytical report examining the TCBX activities. The public will then have an opportunity to assess the practices carried out by the company, including violations of applicable laws and regulations, as well as the conduct of certain shareholders and business partners. Our report will also examine allegations involving individuals connected to financial-sector regulators and law enforcement. Corruption, manipulation of data, regulatory non-compliance, and the submission of potentially misleading reports represent only a small part of the concerns we intend to address. We believe the time has come to initiate short positions. Our forthcoming publications are expected to raise significant questions about the company and could have broader implications for confidence in the U.S. financial sector. As for clients and stakeholders of the financial institution, We strongly recommend that clients safeguard their funds and consider withdrawing them in the near term. Stay tuned for further updates and the release of our detailed findings. |
||||||
| Ransomware | Lansing Urgent Care id31799 View details | United States | — | pending | ||
|
Lansing Urgent Care provides a range of urgent care services for both adults and children, including on-site medications, lab tests, and X-rays. Their facilities are designed for quick visits, with an average wait time of under one hour, and they offer telemedicine options for added convenience. The company caters to patients seeking immediate medical attention, sports physicals, and occupational health services. With multiple locations in Lansing, Okemos, and surrounding areas, they aim to deliver friendly and efficient healthcare. |
||||||
| Ransomware | Otter Tail County, Minnesota id31785 View details | United States | — | pending | ||
|
https://ottertailcounty.gov/ |
||||||
| Ransomware | https://pacific-construction.com/ id31669 View details | United Kingdom | Construction / Real Estate | — | ||
|
Pacific Construction is a company operating in the construction and real estate sector, based in the United Kingdom. The company provides various services related to construction and property development. Pacific Construction was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | https://pacific-construction.com/ id31669 View details | United Kingdom | Construction / Real Estate | — | ||
|
project data client data contract |
||||||
| Ransomware | cambrialawfirm.com id31670 View details | Canada | — | — | ||
|
personal and medical cards of all clients. |
||||||
| Ransomware | clgroup id31657 View details | United States | Finance / Legal / Insurance | — | ||
|
CLGroup operates in the finance, legal, and insurance sector in the US, providing various services to its clients. The company's offerings cater to the needs of its customers in these sectors. CLGroup was listed as a ransomware victim associated with IncranSom. |
||||||
| Ransomware | clgroup id31657 View details | United States | Finance / Legal / Insurance | — | ||
|
Compunnel, founded in 1994 and headquartered in Plainsboro, New Jersey, provides information technology consulting and staffing, custom business application development, and eLearning services |
||||||
| Ransomware | gamaus.com id31652 View details | United States | IT | — | ||
|
Gamaus.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to clients in the US. Gamaus.com was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | gamaus.com id31652 View details | United States | IT | — | ||
|
https://www.zoominfo.com/c/greater-austin-merchants-cooperative-association/98978085 greater-austin-merchants-cooperative-association 400gb |
||||||
| Ransomware | BEDC.COM.AU id31599 View details | Australia | Education | — | ||
|
BEDC.COM.AU is an entity operating within the education sector in Australia. The organization is involved in providing educational services. BEDC.COM.AU was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | BEDC.COM.AU id31599 View details | Australia | Education | — | ||
|
Brighton East Dental Clinic (BEDC) is a family dental clinic dedicated to providing comprehensive dental care for families in Brighton, Caulfield, and Bentleigh. They offer a wide range of services including kids dentistry, general dentistry, cosmetic procedures, and preventative care, with a strong emphasis on patient needs and comfort. With over 30 years of experience, their team of certified dentists focuses on creating healthy, happy smiles while accepting all major health funds. The clinic is known for its convenient evening hours and commitment to emergency dental care. Employees: 50 Revenue: $5 Million Industry: Dental Practice Management Phone Number: +61 395788500 |
||||||
| Ransomware | diabetesandmetabolism.com id31600 View details | United States | Healthcare / Pharma | — | ||
|
Diabetesandmetabolism.com is a US-based online resource focused on diabetes and metabolism, providing information and support within the healthcare sector. The website likely offers educational content, news, and resources related to diabetes management and metabolic health. Diabetesandmetabolism.com was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | diabetesandmetabolism.com id31600 View details | United States | Healthcare / Pharma | — | ||
|
Diabetes and Metabolism Specialists is a specialty medical clinic located in San Antonio, TX, focused on the diagnosis and treatment of endocrine-related medical conditions. The clinic is staffed by board-certified endocrinologists, nurse practitioners, and certified diabetes educators who provide comprehensive care and education for chronic conditions such as diabetes, hyperparathyroidism, and metabolic syndrome. They emphasize professionalism and patient education, ensuring that clients understand their diagnoses and treatment options. The intended clients are individuals seeking specialized care for endocrine disorders and metabolic conditions. Employees: 50 Revenue: $5.5 Million Industry: Hospitals & Physicians Clinics Phone Number: (210) 494-3739 |
||||||
| Ransomware | stuartandassociates.com id31646 View details | United States | — | — | ||
|
Stuart & Associates Commercial Flooring, Inc. specializes in providing high-quality commercial flooring solutions designed to enhance customer experiences. They offer a three-year warranty on new installations when clients purchase maintenance programs, ensuring satisfaction and value throughout the process. The company features a design center with extensive product samples and emphasizes delivering projects on budget and on schedule. Their target clients include businesses seeking safe, comfortable, and aesthetically pleasing flooring options. Employees: 50 Revenue: $6.4 Million Industry: Construction Management Phone Number: (316) 267-0743 |
||||||
| Ransomware | Louisville Bar Association id31481 View details | United States | NGOs / Associations | — | ||
|
Loubar.org is a US-based organization operating in the NGOs and Associations sector, providing services and support to its members and community. The organization is likely focused on promoting social causes and advocating for the interests of its constituents. Loubar.org was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | Louisville Bar Association id31481 View details | United States | NGOs / Associations | — | ||
|
The Louisville Bar Association (LBA) provides a range of services including membership benefits, legal job placement, continuing legal education (CLE), and public service initiatives. It aims to support legal professionals at all stages of their careers while promoting diversity and community engagement within the legal field. The LBA also offers resources for individuals seeking legal representation and hosts various events and awards to recognize outstanding contributions in the legal community. Their intended clients include legal professionals, law firms, and individuals in need of legal assistance in the Louisville area. |
||||||
| Ransomware | ATMS id31462 View details | India | Other | — | ||
|
ATMS is an entity operating in the other sector in India, providing various services. The company is based in India and offers its services to clients. ATMS was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | ATMS id31462 View details | India | Other | — | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
||||||
| Ransomware | vprj.org id31352 View details | United States | NGOs / Associations | — | ||
|
vprj.org is a US-based organization operating in the NGOs and Associations sector. The entity provides various services and support to its members and community. vprj.org was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | vprj.org id31352 View details | United States | NGOs / Associations | — | ||
|
The Virginia Peninsula Regional Jail (VPRJ) is a state-authorized, regional correctional facility located in Williamsburg, Virginia, USA. Opened in 1997, VPRJ provides short-to-medium-term detention services, ensuring public safety and order across the Virginia Peninsula region under the governance of a multi-jurisdictional jail board. |
||||||
| Ransomware | lantisnet.com id31244 View details | United States | IT | — | ||
|
Lantisnet.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering its services to clients in the US. Lantisnet.com was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | lantisnet.com id31244 View details | United States | IT | — | ||
|
Lantis Enterprises, Inc. is an American consulting and management organization historically rooted in rural healthcare, skilled nursing, and senior living operations. Headquartered in Spearfish, South Dakota, the firm has expanded its focus to cross-industry advisory services |
||||||
| Ransomware | Loyalist College id31243 View details | Canada | Education | — | ||
|
Loyalist College is a public college located in Belleville, Ontario, Canada, offering a range of programs in fields such as business, health sciences, and technology. The college provides education and training to students in the Canadian province of Ontario. Loyalist College was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | Loyalist College id31243 View details | Canada | Education | — | ||
|
The management of this institution was repeatedly warned about the disclosure of hundreds of personal data. Each of you who is faced with the consequences of the leak can be absolutely sure that the management of Loyalist College absolutely does not care about its students, employees and partners. ------------------------- Loyalist is Ontario's Destination College, empowering students, faculty, staff, and partners through experiential, industry cluster-based education, training and applied research programs. The College provides job-ready graduates for, and knowledge transfer to, industry and the community. |
||||||
| Ransomware | TRULITE GLASS & ALUMINUM SOLUTIONS id31240 View details | United States | Manufacturing / Engineering | — | ||
|
TRULITE GLASS & ALUMINUM SOLUTIONS is a US-based company operating in the manufacturing and engineering sector, offering glass and aluminum solutions. The company provides various products and services to its customers. TRULITE GLASS & ALUMINUM SOLUTIONS was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | TRULITE GLASS & ALUMINUM SOLUTIONS id31240 View details | United States | Manufacturing / Engineering | — | ||
|
TRULITE GLASS & ALUMINUM SOLUTIONS Date: August 2026 Overview Trulite Glass & Aluminum Solutions, a portfolio company of Truelink Capital (Los Angeles, CA), is a leading North American fabricator and distributor of architectural glass and aluminum systems. Headquartered in Alpharetta, Georgia, the company operates 40+ fabrication and distribution facilities across the United States and Canada, serving the commercial construction industry. Trulite was founded in 1978 and has undergone significant expansion through acquisitions — including Vitro America, Western States Glass, AGC Fabrication, Super Sky Products, American Insulated Glass, and others. In October 2022, Truelink Capital acquired Trulite from Sun Capital Partners. The company generates estimated annual revenue of $800M–$1.2B and employs 2,000–3,500 people. Incident We have obtained full and unrestricted access to Trulite's internal infrastructure. The total volume of exfiltrated data exceeds 8 terabytes. Data in Our Possession The dataset includes but is not limited to: - Complete corporate databases — ERP system (Microsoft Dynamics AX), CRM, operational databases - Financial records — multi-year Profit & Loss statements by branch, EBITDA schedules, debt covenant compliance calculations, 13-week cash flow forecasts, weekly and monthly financial reporting packages prepared for private equity ownership - M&A documentation — Confidential Information Memorandums (CIM), executed Stock Purchase Agreements, acquisition pipeline documents, due diligence materials, corporate structure charts with ownership percentages - Private equity communications — internal correspondence and reporting between Trulite management and fund ownership (Sun Capital Partners, Truelink Capital) - Board of Directors materials — governance records, board presentations, strategic planning documents - HR and employee data — personnel records, payroll, benefits information - Customer and vendor data — contracts, pricing agreements, project documentation, accounts receivable/payable - IT infrastructure documentation — network architecture, system configurations, credentials - Operational data — production records, logistics, fleet management, facility documentation across all 40+ locations Proof of Access Sample data will be published to confirm the scope and authenticity of the breach. Full data publication will follow if no resolution is reached. Contact The Trulite management team has been contacted directly and provided with instructions to initiate private negotiations. A deadline has been communicated. This is the only public statement at this time. Further updates — including data samples — will follow according to the established timeline. |
||||||
| Ransomware | pushidrosal.id id31201 View details | Indonesia | Other | — | ||
|
Pushidrosal.id is an entity based in Indonesia, operating in the other sector. The entity's specific offerings are not well-documented, but it is known to be located in the country of Indonesia. Pushidrosal.id was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | pushidrosal.id id31201 View details | Indonesia | Other | — | ||
|
* |
||||||
| Ransomware | lccgroup.com id31202 View details | Philippines | Construction / Real Estate | — | ||
|
LCC Group is a Philippines-based company operating in the construction and real estate sector, offering various services to its clients. The company is involved in development and management of properties. LCC Group was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | lccgroup.com id31202 View details | Philippines | Construction / Real Estate | — | ||
|
LCC - Liberty Commercial Center, Inc is one of the pioneering retail establishments in the Bicol Region. Based in the dynamic province of Albay, LCC primarily operates supermarkets, department stores, malls, and food establishments. LCC is also engaged in property development. Banking on the cherished Filipino trait of hospitality, LCC's corporate tagline - The company's Best For You empowers its stakeholders and corps of new - generation and seasoned managers to commit themselves to a market stewardship that puts a high premium on rewarding LCC customers for their loyalty and patronage. LCC's growth is rooted in the Filipino spirit of entrepreneurship as an agent of change and progress. Over 75 years of retailing knowhow and quality service continue to touch the lives of its Bicolano consumers and their communities www.lcc.com.ph |
||||||
| Ransomware | https://geleximco.vn/ id31203 View details | Viet Nam | Manufacturing / Engineering | — | ||
|
Geleximco is a Vietnam-based company operating in the manufacturing and engineering sector, providing various products and services. The company is involved in multiple industries, including construction and infrastructure development. Geleximco was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | https://geleximco.vn/ id31203 View details | Viet Nam | Manufacturing / Engineering | — | ||
|
200gb data |
||||||
| Ransomware | clintonhealthaccess.org id31200 View details | United States | NGOs / Associations | — | ||
|
Clinton Health Access Initiative is a US-based non-governmental organization operating in the healthcare sector, providing access to medicines and health services. The organization works to improve healthcare systems in various countries. Clinton Health Access Initiative was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | clintonhealthaccess.org id31200 View details | United States | NGOs / Associations | — | ||
|
This Clinton foundation sponsors the sterilization of women in Africa and South America. With the help of this foundation, organs harvested criminally by transplant surgeons from people in Third World countries are legalized to improve the quality of life of the rich in capitalist countries, including the United States. We have irrefutable evidence of their secret accounts, including transactions in cryptocurrency, from which transplanted organs were purchased to replace Bill Clinton's wife, Hillary Clinton. |
||||||
| Ransomware | Oleoductos del Valle id31199 View details | Argentina | Energy | — | ||
|
Oleoductos del Valle is an energy sector company based in Argentina, involved in the transportation of oil and related energy products. The company operates in the energy sector, providing essential services in Argentina. Oleoductos del Valle was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | Oleoductos del Valle id31199 View details | Argentina | Energy | — | ||
|
During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include: 1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severance calculations and compensation agreements. 2.Financial and regulatory reports filed with CNV and BYMA, including documents related to rating agencies (Moody's) and internal shareholder agreements. 3.Tax declarations and reports submitted to AFIP (Sicore, Ganancias, DDJJ IVA). 4.Documents related to tariff policy and SEN interactions, including WACC and TIR calculations used in tariff reviews. 5.Incident reports and environmental documentation, including reports on spills in Catriel and Medanito, as well as Rosen OSSR technical reports on pipeline conditions. 6.Confidentiality agreements with key partners, including Halliburton, Horizon, YPF, Otasa, McKinsey, and KPMG. 7.Internal whistleblower channel materials (Ley 27.401), including internal complaints and compliance reports. 8.Documents related to dividend payments and banking transactions. 9.Personal data of directors, candidates, and key employees, including ID numbers and CVs. |
||||||
| Ransomware | ecfa.org id31167 View details | United States | NGOs / Associations | — | ||
|
The Evangelical Council for Financial Accountability (ECFA) is a US-based nonprofit organization that provides accreditation to Christian ministries and churches, promoting financial transparency and accountability. ECFA offers resources and training to its members, aiming to enhance their financial management and governance practices. Ecfa.org is listed as a ransomware victim associated with incransom |
||||||
| Ransomware | ecfa.org id31167 View details | United States | NGOs / Associations | — | ||
|
The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in collective revenue. |
||||||
| Ransomware | quantinuum.com id31147 View details | United States | IT | — | ||
|
Quantinuum.com is a US-based company operating in the IT sector, providing various technology solutions. As a leading entity in its field, it offers innovative services to its clients. Quantinuum.com was listed as a ransomware victim associated with incransom. |
||||||
| Ransomware | quantinuum.com id31147 View details | United States | IT | — | ||
|
Quantinuum is a quantum computing company that develops advanced quantum computers, software, and cybersecurity solutions to solve complex scientific and industrial challenges. The company provides full-stack quantum technologies for areas such as materials science, drug discovery, encryption, artificial intelligence, and optimization, helping enterprises and researchers accelerate innovation through quantum computing. The leak dates back to pre-IPO. QUANTINUUM deliberately withheld this information from investors. The exact amount of stolen data will be revealed after publishing. |
||||||
| Ransomware | PARTNERED HEALTH GROUP id31063 View details | Australia | Healthcare / Pharma | — | ||
|
PARTNERED HEALTH GROUP is a healthcare organization based in Australia, operating within the healthcare and pharmaceutical sector. The group likely provides medical services and support to patients and healthcare providers. PARTNERED HEALTH GROUP was listed as a ransomware victim associated with incransom |
||||||
| Ransomware | PARTNERED HEALTH GROUP id31063 View details | Australia | Healthcare / Pharma | — | ||
|
PARTNERED HEALTH GROUP — Australia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Industry: Healthcare — Primary Care, Occupational Health, Psychology, Telehealth Headquarters: Australia (NSW, QLD, VIC, WA, ACT) Owner: Quadrant Private Equity Clinics: 60+ nationwide Brands: Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, TeleWell Website: partneredhealth.com.au PENDING ACQUISITION: Bupa — ~$450,000,000 AUD Announced July 2, 2026 (Australian Financial Review) ACCC and FIRB regulatory approval pending. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ BREACH SUMMARY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Date of access: 23 June 2026 Data exfiltrated: 3.2 TB Total files: 2,298,203 Servers accessed: 21 (9 AD Controllers + 11 Best Practice Medical Servers + 1 Central SQL Server) SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf, VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups Clinics compromised: 21 locations across 5 states/territories Patient records: 17,727+ named patient files identified Staff HR files: Full employee records including passports, AHPRA registrations, tax declarations Period of data: 1999 — 2026 (27 years) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHAT WE HAVE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ▪ Complete patient medical records from 21 GP clinics — consultation notes, referral letters, pathology results, diagnostic imaging reports, prescriptions ▪ Full SQL database dumps — ZedMed (patient management), Payroll (all staff salaries), DocPays (doctor payments), VectraplexECG (cardiac/ECG monitoring data) ▪ 11 complete Best Practice patient database backups — one per clinic — including BPSPatients, BPSDocuments (up to 48 document partitions per clinic) ▪ Staff HR files — employment contracts, passport scans, AHPRA medical registrations, tax file declarations, superannuation details, performance reviews ▪ Bupa corporate data — direct billing agreements, fund tables for all Australian states, patient invoices, corporate program documents (Bronze/Silver/Gold), and active Bupa web portal session cookies ▪ Financial records — QuickBooks databases (2004-2026), Medicare billing, DVA remittances, private health fund claims ▪ Clinical governance — full RACGP accreditation files, patient consent templates, internal clinical audit data ▪ 27 years of accumulated medical data (1999-2026) across ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health was given the opportunity to resolve this matter privately and protect patient data. Instead of acting in the interest of their patients, they spent 22 days in silence, hired lawyers, and obtained a court injunction that has no practical effect outside Australian jurisdiction. Their public statement of July 15 describes the breach as affecting "some" data from "some" clinics. This is misleading. The reality: 3.2 terabytes. 2.3 million files. 21 servers. 27 years of patient medical history. Every clinic server in their network was accessed. Complete SQL database dumps were taken including the central patient management system and payroll for every employee. And critically — the data includes Bupa's own corporate information: billing agreements, fund pricing tables for every Australian state, named patient invoices, and active browser session cookies from Bupa's login, corporate, and web portals. We understand this acquisition matters. $450 million is a significant transaction. A full data publication would create material regulatory complications with the ACCC and FIRB review process. We trust the board and advisors at Quadrant understand what that means. This is not a threat. This is a deadline. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ DEADLINE: [DATE + 10 DAYS] ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health has 10 days to resume negotiations and reach a settlement. If no agreement is reached: Stage 1 — Complete file tree listing (2.3M files) + all HR/staff records published Stage 2 — SQL databases (ZedMed, Payroll, ECG) released for download Stage 3 — Bupa corporate data, fund tables, billing agreements, session data published. ACCC, FIRB, and Bupa executive leadership notified directly. Stage 4 — Full 3.2 TB data dump made available for public download. |
||||||