Ransomware Group intelligence
Embargo
ActiveTrack Embargo with 41 published victims and 1 known leak locations in a single intelligence view.
Overview
Embargo is tracked by Breach House as a ransomware group with 41 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion |
Top Activity Sectors (13)
Typical Attacks (22)
▼How Embargo typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Embargo.
-
What they do: Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named “Perf_sys.”
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.003 Windows Command Shell Execution
What they do: Embargo has utilized a BAT script to disable security solutions.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Embargo has leveraged Windows Native API functions to execute its operations.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: Embargo has created persistence through the DLL variant of the MDeployer toolkit by creating a service called irnagentd that launches after the system is rebooted in Safe Mode.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
What they do: Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1068 Exploitation for Privilege Escalation Privilege Escalation
What they do: Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD).
What that means: Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480.002 Mutual Exclusion Stealth
What they do: Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function.
What that means: Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
-
T1679 Selective Exclusion Stealth
What they do: Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1688 Safe Mode Boot Defense Impairment
What they do: Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1007 System Service Discovery Discovery
What they do: Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`.
What that means: Adversaries may try to gather information about registered local system services.
-
T1057 Process Discovery Discovery
What they do: Embargo has utilized MS4Killer to detect running processes on the victim device.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1657 Financial Theft Impact
What they do: Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (3)
▼Software Embargo has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
LOLBAS (living-off-the-land binaries)
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_RECOVER_FILES_2.txt
Your network has been chosen for Security Audit by EMBARGO Team. We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems. You must contact us before the deadline 2025-05-25 09:37:19 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/ Do not modify any files or file extensions. Your data maybe lost forever. Instructions: 1. Download torbrowser: https://www.torproject.org/download/ 2. Go to your registration link: ================================= http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/[snip] ================================= 3. Register an account then login If you have problems with this instructions, you can contact us on TOX: 9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47 After payment for our services, you will receive: - decrypt app for all systems - proof that we delete your data from our systems - full detail pentest report - 48 hours support from our professional team to help you recover systems and develop Disaster Recovery plan IMPORTANT: After 2025-05-25 09:37:19 +0000 UTC deadline, your registration link will be disabled and no new registrations will be allowed. If no account has been registered, your keys will be deleted, and your data will be automatically publish to our blog and/or sold to data brokers. WARNING: Speak for yourself. Our team has many years experience, and we will not waste time with professional negotiators. If we suspect you to speaking by professional negotiators, your keys will be immediate deleted and data will be published/sold.
HOW_TO_RECOVER_FILES.txt
Your network has been chosen for Security Audit by EMBARGO Team. We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems. You must contact us before the deadline 2024-05-21 06:25:37 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/ Do not modify any files or file extensions. Your data maybe lost forever. Instructions: 1. Download torbrowser: https://www.torproject.org/download/ 2. Go to your registration link: ================================= http://5ntlvn7lmkezscee2vhatjaigkcu2rzj3bwhqaz32snmqc4jha3gcjad.onion/#/[snip] ================================= 3. Register an account then login If you have problems with this instructions, you can contact us on TOX: 9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47 After payment for our services, you will receive: - decrypt app for all systems - proof that we delete your data from our systems - full detail pentest report - 48 hours support from our professional team to help you recover systems and develop Disaster Recovery plan IMPORTANT: After 2024-05-21 06:25:37 +0000 UTC deadline, your registration link will be disabled and no new registrations will be allowed. If no account has been registered, your keys will be deleted, and your data will be automatically publish to our blog and/or sold to data brokers. WARNING: Speak for yourself. Our team has many years experience, and we will not waste time with professional negotiators. If we suspect you to speaking by professional negotiators, your keys will be immediate deleted and data will be published/sold.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (41)
Search, filter and paginate the victim timeline for Embargo. Showing 1–41 of 41.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.maytrucking.com id30108 View details | United States | Transportation / Travel / Logistics | ||
|
May Trucking is a US-based company operating in the transportation sector, providing logistics and travel services. The company is involved in the movement of goods and people across the country. May Trucking was listed as a ransomware victim associated with embargo. |
|||||
| Ransomware | www.maytrucking.com id30108 View details | United States | Transportation / Travel / Logistics | ||
|
May Trucking Company is a family-owned interstate transport carrier founded in 1945, headquartered in Brooks, Oregon. They provide dry freight and temperature-c... - TOTAL QUANTITY OF DATA 1 TB |
|||||
| Ransomware | Auburn Electrical Construction Company id29710 View details | United States | Construction / Real Estate | ||
|
Auburn Electrical Construction Company, Inc. is an innovative contracting firm that profitably provides electrical-related services to our customers. Our goal i... - |
|||||
| Ransomware | https://www.lagoonpark.com/ id27766 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Lagoon Amusement Park , located in Farmington, Utah, is a historic family-owned park operating since 1886. It features a combination of roller coasters (includ... - TOTAL QUANTITY 6 TB |
|||||
| Ransomware | ludlums.com id27602 View details | United States | Manufacturing / Engineering | ||
|
Ludlum Measurements, Inc. (LMI), founded in 1962 in Sweetwater, Texas, designs, manufactures, and supplies radiation detection and measurement equipment used w... - We have 5 TB data including full source codes, client data, and more. |
|||||
| Ransomware | westport.com id27326 View details | United States | Other | ||
|
We connect synergistic technologies to power a cleaner tomorrow. As a leading supplier of affordable, alternative fuel, low-emissions transportation technologie... - TOTAL QUANTITY 1.8 TB |
|||||
| Ransomware | seclore.com id27267 View details | India | IT | ||
|
At Seclore, we believe that cybersecurity should revolve around what matters most—your data. Traditional security perimeters are no longer enough in today’s hyp... - TOTAL QUANTITY 1.3 TB |
|||||
| Ransomware | ubm.hu id27255 View details | Hungary | Agriculture / Food | ||
|
The UBM Group is a leading Hungarian agricultural company, founded in 1996, specializing in the production of compound feed, the trading of feed ingredients (gr... - 300 GB (sensitive data including recipes, documents, contracts, databases) Hungarian language documents will be transl... |
|||||
| Ransomware | nch.com id27191 View details | United States | Services | ||
|
Your leading global experts in industrial solutions. At NCH Corporation, we don’t just sell products—we deliver solutions that keep businesses moving. For ov... - More than 7.3TB of data has been downloaded. |
|||||
| Ransomware | lso.com id24485 View details | Lesotho | Transportation / Travel / Logistics | ||
|
Lone Star Overnight (LSO) is headquartered in Austin, Texas, and, over the last 30 years, has become a leading regional parcel delivery company. LSO has a netwo... - LSO does not understand encryption so we demonstrated for them how encryption works. We have ~500 GB data total includin... |
|||||
| Ransomware | ACTi.com id23288 View details | Taiwan, Province of China | Energy | ||
|
ACTi Corporation, founded in 2003, is a leading application developer with Big Data, Robot, IoT, Cloud and AI Technologies to empower business intelligent solut... - more than 1.5TB of data has been downloaded. |
|||||
| Ransomware | usadebusk.com id22505 View details | United States | Communication / Marketing | ||
|
USA DeBusk provides a comprehensive suite of industrial cleaning and infrastructure maintenance services to a diverse, blue-chip customer base across a broad r... - 2 TB including Contracts, Client Data, Employee Private Data, Incident Reports, and more |
|||||
| Ransomware | Heart of America Medical Centr (HAMC) id21559 View details | United States | Healthcare / Pharma | ||
|
About Heart of America Medical Center A non-profit hospital offering comprehensive medical services, including emergency care, radiology/imaging, surgical cen... - I have your Data 800GB. I will post the data in three stages. You can view some of the files on the link from tor browse... |
|||||
| Ransomware | hawaiiunified.com id20807 View details | United States | Construction / Real Estate | ||
|
HAWAI'I UNIFIED is a licensed General Contractor, Electrical Contractor, Plumbing Contractor, Steel Door Contractor, and Fencing Contractor providing services t... - We hacked Hawai'i Unified. Today, we disclose 65 GB of data. |
|||||
| Ransomware | rotaryeng.com.sg id20553 View details | Singapore | Energy | ||
|
Founded in 1972, Rotary is one of the region’s leading oil and gas infrastructure services companies with extensive international experience offering fully inte... - On 31 May 2025, we hacked rotaryeng.com.sg and exfiltrated 4+ TB of data. Today, we make the first disclosure which incl... |
|||||
| Ransomware | allstarflooring.com id20351 View details | United States | Communication / Marketing | ||
|
All Star Flooring, Inc. is a leading provider of commercial flooring solutions with over 35 years of experience serving the Washington Metropolitan Area, including the District of Columbia, Maryland, and Virginia. The company's headquarters is located at 10742 Tucker Street, Beltsville, MD 20705. - Today, we disclose 140 GB of data. |
|||||
| Ransomware | M&H Electric Fabricators id20350 View details | United States | Manufacturing / Engineering | ||
|
Welcome to M&H Electric Fabricators, where we've been sparking innovation and powering up the automotive electric industry since 1985. Our experience and commitment to excellence have helped us become the leading supplier of wiring harnesses to the automotive aftermarket. - 220gb of electric fabricators |
|||||
| Ransomware | Kingsmen Creatives Ltd. id20006 View details | Singapore | Communication / Marketing | ||
|
Kingsmen Creatives designs roll-out retail environments based off their clients' needs and conceptualize events for their clients. Established in 1976 and headquartered in Singapore, the Group has a network of 21 offices and full service facilities serving global clients today. - |
|||||
| Ransomware | rixos.com id18400 View details | Türkiye | Hospitality / Food & Beverage / Tourism | ||
|
Founded in 2000 and headquartered in Dubai, United Arab Emirates, Rixos Hotels is a Turkish luxury hotel chain. The company operates hotels and resorts across Europe and the Middle East, including properties in Azerbaijan, Egypt, Kazakhstan, Russia, Switzerland, Turkey, Ukraine and the UAE. - We will disclose 1.8 TB of data |
|||||
| Ransomware | Insider Technologies Limited id18263 View details | United Kingdom | IT | ||
|
Based in Manchester, Great Britain, Insider technologies is a leading provider of big data, predictive software security solutions to the banking and payments industry. The company's innovative high volume transactions analytics systems allow card issuers and processors to maintain their systems' integrity and instantly monitor track, analyze and quickly alert them on challenging electronic transactions or operational issues. The solutions integrate seamlessly with all payment authorization systems without any loss in performance. In addition, Insider technologies' reputation management solutions track social media networks enabling clients to better understand and act on key trends and issues that negatively impact shareholder and organizational value. The ability to instantly manage large client data and report key information direct to a single console sets Insider technologies apart. - |
|||||
| Ransomware | tequaly.com id17771 View details | Brazil | Manufacturing / Engineering | ||
|
One of Brazil's largest suppliers of technological systems, maintenance, manufacturing, assembly and services for industries in various segments, which has been successfully partnering with clients in Latin America since 1996. Specialized in offering complete solutions or solutions tailored to your exact needs. Located in Curitiba/PR, Brazil, Tequaly has approximately 100,000 m² of manufacturing area and 5,000 m² of administrative and support area. - -Contracts -Financial data -Engineering data <purification system> <evaporation system> <methanol burning up> .... |
|||||
| Ransomware | myhscu.com id17603 View details | United States | Finance / Legal / Insurance | ||
|
Heritage South Credit Union was originally chartered in 1937 as the Avondale Employees Federal Credit Union. After many years and a couple of name changes, Heritage South Credit Union continues to have a strong presence in Sylacauga, Childersburg, Moody, and Alexander City as a fixture in the community and as a stable and secure financial institution. Heritage South Credit Union has grown to over $160 million in assets and over 14,000+ members. - 300 GB data including: - debit card numbers - account numbers - SSN - address - phone - email - DOB - current balances - debts - loans - insurance Here's data for CEO: JAMIE MCCAA PAYTON 3993 ODENS MILL RD SYLACAUGA AL 35151 DOB: 1969-11-18 SSN: 423-04-5662 Phone: 256-872-2885|256-245-0777 Email: [email protected]|[email protected]|[email protected] SPOUSE: CHRIS PAYTON (416-82-5751 1967-12-01) |
|||||
| Ransomware | annegrady.org id17561 View details | United States | Communication / Marketing | ||
|
Anne Grady Services provides a vast array of assistance for adults and children with intellectual disabilities. - Anne Grady Services provides a vast array of assistance for adults and children with intellectual disabilities. Call The Anne Grady Center at 419-866-6500 to be connected to our administrative offices, therapy programs, and leadership team. |
|||||
| Ransomware | Heritage South Credit Union id17534 View details | United States | Finance / Legal / Insurance | ||
|
Heritage South Credit Union was originally chartered in 1937 as the Avondale Employees Federal Credit Union. After many years and a couple of name changes, Heritage South Credit Union continues to have a strong presence in Sylacauga, Childersburg, Moody, and Alexander City as a fixture in the community and as a stable and secure financial institution. Heritage South Credit Union has grown to over $160 million in assets and over 14,000+ members. - 300 GB data including: - debit card numbers - account numbers - SSN - address - phone - email - DOB - current balances - debts - loans - insurance Here's data for CEO: ... |
|||||
| Ransomware | alansarioman.com id16555 View details | Oman | Construction / Real Estate | ||
|
Al Ansari is a provider of integrated building, infrastructure and engineering solutions. The group was established in 1975 in response to the growing needs of the infrastructure and construction developments in Oman. Over the years, the group has earned a reputation of delivering high quality service in a timely manner. Al Ansari has undertaken many vital construction projects that have contributed to the development of the local infrastructure. Al Ansari is registered as an"Excellent Grade" company with the Tender Board of Oman & is also certified by the Quality Management Standard ISO 9001:2008. With a work force of over 4,000, the group strongly believes in investing into HRD (Human Resource Development) initiatives to enhance individual's skill and competencies and produce "Extraordinary" human capital. - Around 1 TB of critical and confidential data were downloaded from the Al Ansari Oman company's network |
|||||
| Ransomware | backyarddiscovery.com id15768 View details | United States | Communication / Marketing | ||
|
Backyard Discovery is built for families. From a child’s first playset to structures that guard the parents’ newest outdoor interests, our products are meant to play a role in families’ lives for years and years. You can find our dedicated team hard at work in our Pittsburg, KS headquarters and diligently focused at every one of our distribution centers. Each of our innovators and specialists is passionate about helping families enjoy wonderful moments right in their own backyards — and you can see that focus in our high-quality gazebos, pergolas, swing sets, playhouses, and backyard leisure products. - ~1TB of confidential data. |
|||||
| Ransomware | American Associated Pharmacies id15274 View details | United States | Healthcare / Pharma | ||
|
American Associated Pharmacies (AAP) is a member-owned cooperative of over 2,000 independent pharmacies working together as a cohesive network. AAP in partnership with its subsidiaries, Associated Pharmacies, Inc. (API), Arete Pharmacy Network, and AllyScripts, provides the tools and resources needed for members to improve their bottom line and differentiate themselves from competitors. AAP members not only receive savings on brand prescriptions, generic prescriptions and OTC products through the API warehouse and their negotiated prime vendor agreement, but they also receive negotiated competitive managed-care contracts through the Arete Pharmacy Network. In addition to offering solutions such as API and Arete Pharmacy Network, AAP provides members access to a full-service specialty pharmacy, AllyScripts, that allows pharmacies to retain their patients and compete in the growing specialty segment without the costly investment. AAP is able to provide its members with the support and customized solutions they need to succeed in the marketplace. - It seems AAP does not care about their data. AAP has paid 1.3 million for decrypt and owe another 1.3 million for 1.469 TB of their data. |
|||||
| Ransomware | wexfordcounty.org id15168 View details | Jordan | Public Sector | ||
|
Located in Northern Lower Michigan, Wexford County boasts a population of approximately 35,000, with a combination of an industrial/recreational demographic base. - 1 TB Data Network Admins: Joe Porterfield ([email protected]) Jami Bigger ([email protected]) 231-779-9452 Passwords: ["August24!", "September24!", "October24!"] MSSP: Sophia Masotti-Jordan ([email protected]) 616-856-5678 |
|||||
| Ransomware | mh-m.org id15165 View details | United States | Healthcare / Pharma | ||
|
Memorial Hospital and Manor celebrated its 50th Anniversary in 2010. Memorial Hospital was officially dedicated on Sunday, April 3, 1960, and opened its doors to receive patients the following day. The 80-bed hospital was built under the Hill-Burton Hospital Survey & Construction Act of 1946. The Hill-Burton Act initiated the concept of local, state, and federal cost sharing of healthcare facilities, and provided federal funds for construction and renovation of more than 9,000 medical facilities, particularly in lower income areas. While two-thirds of the money was provided by the Federal government and the State of Georgia, Memorial Hospital has always been operated by the Hospital Authority of the City of Bainbridge and Decatur County. Prior to the opening of Memorial Hospital, two private hospitals served the healthcare needs of Decatur and surrounding counties. In 1916, Riverside Hospital was built and operated by Dr. J. D. Chason, Dr. Gordon Chason, Dr. R. F. Wheat, and Dr. Willie Lee Wilkinson. Shortly after the Riverside Hospital was built, Dr. A.E.B. Alford came to Bainbridge and built the Bainbridge Hospital. The Flint River provided easy access to these hospitals for people in rural areas and nearby towns, making Bainbridge a healthcare center for the tri-state area. Memorial Hospital was given its name in memoriam to those pioneers who made Bainbridge the medical center of Southwest Georgia, Northern Florida, and Southeastern Alabama for many decades. - 1.15 TB Data |
|||||
| Ransomware | Memorial Hospital & Manor id15158 View details | United States | Healthcare / Pharma | ||
|
Memorial Hospital and Manor celebrated its 50th Anniversary in 2010. Memorial Hospital was officially dedicated on Sunday, April 3, 1960, and opened its doors to receive patients the following day. The 80-bed hospital was built under the Hill-Burton Hospital Survey & Construction Act of 1946. The Hill-Burton Act initiated the concept of local, state, and federal cost sharing of healthcare facilities, and provided federal funds for construction and renovation of more than 9,000 medical facilities, particularly in lower income areas. While two-thirds of the money was provided by the Federal government and the State of Georgia, Memorial Hospital has always been operated by the Hospital Authority of the City of Bainbridge and Decatur County. Prior to the opening of Memorial Hospital, two private hospitals served the healthcare needs of Decatur and surrounding counties. In 1916, Riverside Hospital was built and operated by Dr. J. D. Chason, Dr. Gordon Chason, Dr. R. F. Wheat, and Dr. Willie Lee Wilkinson. Shortly after the Riverside Hospital was built, Dr. A.E.B. Alford came to Bainbridge and built the Bainbridge Hospital. The Flint River provided easy access to these hospitals for people in rural areas and nearby towns, making Bainbridge a healthcare center for the tri-state area. Memorial Hospital was given its name in memoriam to those pioneers who made Bainbridge the medical center of Southwest Georgia, Northern Florida, and Southeastern Alabama for many decades. - 1.15 TB Data |
|||||
| Ransomware | weisermemorialhospital.org id14512 View details | United States | Healthcare / Pharma | ||
|
Weiser Memorial Hospital is a full service not-for-profit community hospital that has been serving the healthcare needs of Washington County and surrounding areas since 1950. In recent years, the hospital has grown to include the Surgical and Specialty Clinic that provides access to numerous specialists, as well as Family Medical Center, a family practice clinic that provides access to local family physicians. - 200 GB Data Adam Hollman likes to waste time. Persons Responsible: Adam Hollman ( [email protected] +1-612-887-1547) David Allwein ( [email protected] +1-208-230-1092 ) Steven Hale ( [email protected] +1-808-282-6001 / +1-208-549-4450) |
|||||
| Ransomware | pioneerworldwide.com id13578 View details | United States | Communication / Marketing | ||
|
Founded in 1917, Pioneer Balloon Company is the world's premier manufacturer of latex balloons, with a diversified range of products that includes Microfoil® balloons and Bubble Balloons. Additionally, Pioneer offers innovative product solutions to customers in the advertising, entertaining, decorating, and social expressions markets. Headquartered in Wichita, KS, USA, Pioneer has facilities in the United States, Canada, England, Australia, Mexico, and Brazil. - 1.65 TB |
|||||
| Ransomware | summervillepolice.com id13577 View details | United States | Construction / Real Estate | ||
|
The Summerville Police Department is committed to building relationships with community members while providing the highest level of service in shooting black children. - 1.71 TB |
|||||
| Ransomware | diligentusa.com id13318 View details | Services | |||
|
Diligent Delivery Systems provides transportation services for businesses within varying industries. Major clients include WorldPac and PharMerica. The company is currently facing tight liquidity and debt default due 23 million cash uses within the past 18 months. Management has been tasked with refinancing existing debt, sourcing a new investor, or selling the business. - Total leak size: 600+ GB For any clients and buyers who have interest in working with Diligent or investing/buying this company, we have invaluable data for you. All documents and the entire collection of emails since January 1 2024 for: - Larry Browne (CEO) - Darl Petty (CFO) - Carlos Navarro (COO) - Alan Geraldi (Legal Counsel) Additionally, we have database backups, documents belonging to clients (protected by NDA), and more. If you had doubts about the financial situation of this company, no need to doubt. We will be releasing the entire collection shortly. The company will try to deny that they have these financial difficulties and that they are trying to sell the company, but these emails and documents tell different story. Some contacts for you: Larry Browne [email protected] [email protected] (713) 906-4385 (281) 854-1300 713-906-9253 713-906-4385 President Darl Petty [email protected] 713-906-6167 281-854-1313 CFO Carlos Navarro [email protected] 713.205.8861 (713)275-2555 713-377-2799 COO Alan Geraldi [email protected] (281)948-2604 (832)300-3595 General Counsel (Legal) Lisa Musick [email protected] (713)906-7317 (281)854-1301 Executive Assistant Scott Bruder [email protected] (713)906-0070 (281)854-1317 VP of National Sales Automative Dawn Vesey [email protected] 615.719.0481 HR Director Tim Barrett [email protected] 615-362-6799 629-335-3399 Director of Information Technologies Ed Saddler [email protected] (346)988-7464 Information Technology Level 2 Support Ron Lewis [email protected] (281)728-3174 (281)854-1355 IT Support Manager Jakob Akin [email protected] 6292438907 6292438907 Systems Administrator |
|||||
| Ransomware | gerard-perrier.com id13254 View details | France | Manufacturing / Engineering | ||
|
Gerard Perrier Industrie SA is a France-based company that provides electrical and electronic automation solutions to industry including design and manufacturing, installation and maintenance. The Company operates through its subsidiaries, including SAS Geral, which designs and manufactures electronic and electrical automation and control equipment; SAS Soteb, which installs and maintains different types of electrical and automation equipment, SAS Ardatem, which specializes in the nuclear energy sector and ensure technical assistance, among others. Gerard Perrier Industrie's customers include manufacturers of machinery, professional equipment and capital goods, and electrical departments of industrial production sites in the chemical, mechanical and food processing sectors, among others. The Company’s activities also include provision of energy-related services, installation, and maintenance services, and construction of electrical and electronic assemblies. - 1,4 T Data |
|||||
| Ransomware | dmedelivers.com id12917 View details | United States | Communication / Marketing | ||
|
Marketing, Printing, Logistics - 1 TB+ databases, source code, client files |
|||||
| Ransomware | shamrocktradingcorp.com id12657 View details | United States | Transportation / Travel / Logistics | ||
|
Shamrock Trading Corporation is the parent company for a family of brands in transportation services, finance and technology. The company offers transportation logistics, discount programs, and international trade financing. - |
|||||
| Ransomware | orga-soft.de id12601 View details | Germany | Construction / Real Estate | ||
|
Software Development - SQL BASES AND SOURCES 650 GB, LINK WILL BE AVAILABLE SOON |
|||||
| Ransomware | rexmoore.com id12397 View details | United States | Manufacturing / Engineering | ||
|
Founded in 1922 and headquartered in Sacramento, California, Rex Moore is a family-owned and managed company, providing electrical and integrated systems engineering, manufacturing, construction and maintenance. The company performs both design/build and bid work for most electrical and low voltage projects. - DATA will be available soon. SQL Databases + big amount of Documents. |
|||||
| Ransomware | firstmac.com.au id12198 View details | Australia | Finance / Legal / Insurance | ||
|
Firstmac Limited is an Australian owned company with experience in home and investment loans. They have a range of market insurance products backed by international company, Allianz Group. International ratings agency Standard & Poors gives Firstmac its highest possible ranking (strong) for loan serviceability abilities. - 500+ GB full databases, source codes, sensitive customer data |
|||||
| Ransomware | mulfordconstruction.com id12080 View details | United States | Construction / Real Estate | ||
|
Heavy Civil Contracting, Earthwork and Utilities - 2 TB data will be disclosed soon |
|||||