Ransomware Group intelligence
Incransom
ActiveTrack Incransom with 1013 published victims and 7 known leak locations in a single intelligence view.
Overview
Incransom is tracked by Breach House as a ransomware group with 1013 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 7 | Onion service | Up checked 1h ago | incbacg6bfwtrlzwdbqc55gsfl763s3twdtwhp27dzuik6s6rwdcityd.onion |
| Leak location 6 | Onion service | Up checked 1h ago | incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion |
| Leak location 2 | Onion service | Down checked 1h ago | incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd.onion |
| Leak location 5 | Web location | Down checked 1h ago | incapt.su |
| Leak location 4 | Web location | Down checked 1h ago | incapt.blog |
| Leak location 1 | Onion service | Down checked 1h ago | incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion |
| Leak location 3 | Web location | Down checked 1h ago | incbackend.top |
Top Activity Sectors (18)
- Communication / Marketing 173
- Healthcare / Pharma 112
- Finance / Legal / Insurance 110
- Services 73
- Manufacturing / Engineering 69
- Education 56
- Not identified 54
- Construction / Real Estate 53
- Public Sector 44
- IT 39
- Retail / E-commerce 27
- NGOs / Associations 24
- Transportation / Travel / Logistics 22
- Energy 21
- Hospitality / Food & Beverage / Tourism 16
- Agriculture / Food 13
- Telecommunications 11
- null 1
Typical Attacks (35)
▼How Incransom typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via INC Ransom, INC Ransomware.
-
T1588.002 Tool Resource Development
What they do: INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: INC Ransom has used compromised valid accounts for access to victim environments.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566 Phishing Initial Access
What they do: INC Ransom has used phishing to gain initial access.
What that means: Adversaries may send phishing messages to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: INC Ransom has used WMIC to deploy ransomware.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.003 Windows Command Shell Execution
What they do: INC Ransom has used `cmd.exe` to launch malicious payloads.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: INC Ransom has uninstalled tools from compromised endpoints after use.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1046 Network Service Discovery Discovery
What they do: INC Ransom has used NETSCAN.EXE for internal reconnaissance.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1049 System Network Connections Discovery Discovery
What they do: INC Ransom has used RDP to test network connections.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: INC Ransom has enumerated domain groups on targeted hosts.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1083 File and Directory Discovery Discovery
What they do: INC Ransomware can receive command line arguments to encrypt specific files and directories.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.002 Domain Account Discovery
What they do: INC Ransom has scanned for domain admin accounts in compromised environments.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1120 Peripheral Device Discovery Discovery
What they do: INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: INC Ransom has used Internet Explorer to view folders on other systems.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1652 Device Driver Discovery Discovery
What they do: INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: INC Ransomware can discover and mount hidden drives to encrypt them.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: INC Ransom has used RDP to move laterally.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1074 Data Staged Collection
What they do: INC Ransom has staged data on compromised hosts prior to exfiltration.
What that means: Adversaries may stage collected data in a central location or directory prior to Exfiltration.
-
T1560.001 Archive via Utility Collection
What they do: INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1071 Application Layer Protocol Command and Control
What they do: INC Ransom has used valid accounts over RDP to connect to targeted systems.
What that means: Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: INC Ransom has used AnyDesk and PuTTY on compromised systems.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1537 Transfer Data to Cloud Account Exfiltration
What they do: INC Ransom has used Megasync to exfiltrate data to the cloud.
What that means: Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
-
T1486 Data Encrypted for Impact Impact
What they do: INC Ransom has used INC Ransomware to encrypt victim's data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: INC Ransomware can issue a command to kill a process on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: INC Ransomware can delete volume shadow copy backups from victim machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: INC Ransomware has the ability to change the background wallpaper image to display the ransom note.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1657 Financial Theft Impact
What they do: INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (9)
▼Software Incransom has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (1013)
Search, filter and paginate the victim timeline for Incransom. Showing 1–100 of 1013.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | New Century Ophthalmology Group id32339 View details | United States | Healthcare / Pharma | ||
|
New Century Ophthalmology Group operates within the healthcare and medicine sector, providing ophthalmic services and patient care in the United States. As a healthcare organization, it handles sensitive patient information and clinical workflows, making it a potential target for cyber threats. This entity is formally listed within the threat-intelligence index as a ransomware victim associated with the threat actor incransom. The listing reflects the observed relationship between the organization and the identified threat actor without disclosing unverified incident details. This catalog entry supports threat-aware monitoring and context for cybersecurity professionals tracking healthcare sector exposures. |
|||||
| Ransomware | New Century Ophthalmology Group id32339 View details | United States | Healthcare / Pharma | ||
|
New Century Ophthalmology is a leading ophthalmology practice located in Raleigh and Oxford, NC, specializing in advanced eye care services including cataract surgery, glaucoma treatment, and oculoplastic procedures. The practice is dedicated to providing personalized, high-quality care with a focus on patient well-being and innovative treatment options. Their team of fellowship-trained specialists utilizes state-of-the-art technology to ensure optimal outcomes for a variety of eye conditions. New Century Ophthalmology serves a diverse clientele seeking comprehensive eye health solutions and aesthetic enhancements |
|||||
| Ransomware | zummocorp.com id32331 View details | United States | IT | ||
|
zummocorp.com operates within the IT sector and is situated in the United States. The entity represents a business organization that was identified within a threat-intelligence index as a ransomware victim linked to the incransom threat actor. This listing type categorizes the entity based on its documented association with a cyber threat campaign targeting IT infrastructure. The entry provides neutral context for cybersecurity professionals monitoring ransomware incidents across sectors and geographic regions. No specific incident details such as data stolen, ransom demands, or breach confirmations are included per strict factual reporting guidelines. |
|||||
| Ransomware | zummocorp.com id32331 View details | United States | IT | ||
|
Zummo is a global incumbent in the design, manufacture and commercialization of automatic fresh fruit juice extraction machines, mainly aimed at the food service and food retail segments. |
|||||
| Ransomware | www.lichtvision.com id32332 View details | United Kingdom | Manufacturing / Engineering | ||
|
www.lichtvision.com operates within the Manufacturing and Engineering sector, based in the United Kingdom. The entity provides specialized technical and operational services relevant to industrial workflows and engineering solutions. This listing type identifies www.lichtvision.com as a ransomware victim within the threat-intelligence index. The associated threat actor and source for this record is incransom. The entry reflects the organization's inclusion in the ransomware victim category linked to this specific threat actor, presented neutrally for catalog purposes. |
|||||
| Ransomware | www.lichtvision.com id32332 View details | United Kingdom | Manufacturing / Engineering | ||
|
Lichtvision specializes in innovative lighting design, focusing on architectural spaces through the use of daylight, artificial light, and immersive media technologies. With a team of 40 designers, architects, and engineers, they provide sustainable and aesthetically pleasing lighting solutions for a variety of projects, including museums, offices, and retail spaces. Established in 1997, Lichtvision has a global presence with studios in major cities and emphasizes a holistic approach to lighting that enhances the quality of life. Their work is characterized by a blend of creativity, technical expertise, and a commitment to ecological sustainability. |
|||||
| Ransomware | www.renorefractories.com id32333 View details | United States | Manufacturing / Engineering | ||
|
www.renorefractories.com operates within the United States manufacturing and engineering sector, providing specialized repair and technical services aligned with industrial operations. The entity is cataloged specifically as a ransomware victim within the threat-intelligence index, linked to the incransom threat actor or source identifier. This listing type indicates documented exposure or impact related to malicious cyber activity targeting organizations in this sector. The description remains neutral and avoids speculation regarding data loss, ransom demands, or confirmed breach details, focusing solely on the entity's classification and associated threat context for analytical reference. |
|||||
| Ransomware | www.renorefractories.com id32333 View details | United States | Manufacturing / Engineering | ||
|
RENO Refractories, Inc. specializes in the manufacturing of refractory products and services for various industrial applications, including aluminum, iron and steel, cement and lime, foundries, mini mills, and hydrocarbon processing. With over 35 years of experience, the company is committed to innovation and quality, providing advanced research and development, technical support, and installation services. Their product offerings include a full range of monolithic products and the revolutionary ElectroCast product line. RENO aims to optimize the profits and safety of their clients by delivering superior refractory technology across North America. |
|||||
| Ransomware | cimbsecurities.com id32334 View details | Malaysia | Finance / Legal / Insurance | ||
|
cimbsecurities.com operates within the Finance, Legal, and Insurance sectors and is associated with the country Malaysia. The entity is documented in this threat-intelligence index under the listing type ransomware victim, with incransom identified as the associated threat actor or source. This record provides neutral context regarding the cybersecurity event connected to the organization without disclosing unverified incident details such as data stolen, ransom demands, or breach confirmation. The inclusion reflects the index's role in mapping real-world entities to active cyber threats for risk assessment and intelligence monitoring purposes. |
|||||
| Ransomware | cimbsecurities.com id32334 View details | Malaysia | Finance / Legal / Insurance | ||
|
Bank |
|||||
| Ransomware | wittmann id32260 View details | Mexico | Manufacturing / Engineering | ||
|
Wittmann operates within the Manufacturing and Engineering sector and is associated with the country Mexico. As a ransomware victim indexed in this threat-intelligence catalog, the entity is documented to illustrate exposure patterns within industrial and engineering supply chains. The listing explicitly associates wittmann with the threat actor incransom, reflecting its inclusion as a ransomware victim case. This entry provides neutral context on the entity's sector, geographic origin, and its classification within the ransomware incident framework. No specific breach details, data loss metrics, or confirmed incident specifics are included, preserving factual integrity and avoiding speculation regarding the nature or scope of the threat. |
|||||
| Ransomware | wittmann id32260 View details | Mexico | Manufacturing / Engineering | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation.NDA files |
|||||
| Ransomware | Oilquip Inc id32253 View details | United States | Services | ||
|
Oilquip Inc is a United States-based company operating within the Services sector, providing professional and technology-driven offerings to clients. As part of the threat-intelligence catalog, Oilquip Inc is formally listed as a ransomware victim associated with the threat actor incransom. This designation reflects its inclusion in the index due to its connection with this specific cyber threat actor within its operational context. The entry documents the entity's status without disclosing unverified incident details, maintaining neutrality and adherence to factual reporting standards for cybersecurity intelligence. |
|||||
| Ransomware | Oilquip Inc id32253 View details | United States | Services | ||
|
Oilquip Inc, established in 1960, is a comprehensive fluid power distributor that specializes in hydraulics, pneumatics, oil conditioning, and system integration. The company is dedicated to providing innovative electro-hydraulic and electro-mechanical solutions while exceeding customer expectations. Their services include design and engineering, fluid conditioning, power generation, and repairs and upgrades, catering to a diverse range of clients. Oilquip prides itself on its customer-focused approach, flexibility, and commitment to excellence in all aspects of its operations. |
|||||
| Ransomware | BENCIVIL id32204 View details | United States | IT | ||
|
BENCIVIL is an entity operating within the US IT sector, cataloged as a ransomware victim within a threat-intelligence index. Its classification reflects its role as an organization impacted by malicious cyber activity targeting information technology infrastructure. The listing explicitly associates BENCIVIL with the threat actor incransom, providing context for its security posture and incident classification. This entry serves threat analysts and cybersecurity professionals seeking structured intelligence on affected entities and linked threat campaigns. The description remains neutral and factual, documenting the entity's designation without extrapolating unverified incident details. |
|||||
| Ransomware | BENCIVIL id32204 View details | United States | IT | ||
|
Benchmark Civil Engineering Services, Inc. is a civil engineering firm based in Allentown, PA, specializing in civil engineering, traffic studies, forensic engineering, and land surveying. The company serves municipalities and clients in the Lehigh Valley and surrounding areas, providing expert services in traffic and transportation engineering, land development, and construction engineering. With a focus on professionalism and integrity, Benchmark is committed to guiding clients through the design, approval, and construction processes. Their highly trained staff utilizes state-of-the-art technology to ensure project success and compliance with regulations. |
|||||
| Ransomware | Rohloff Group id32198 View details | South Africa | Services | ||
|
Rohloff Group operates within the Services sector and is located in South Africa (country code ZA). The entity functions as a commercial organization providing service-oriented offerings, though specific operational details beyond its sector classification are not disclosed in public threat-intelligence records. This listing type identifies Rohloff Group as a ransomware victim associated with the incransom threat actor or source. The catalog entry reflects the entity's inclusion in the threat-intelligence index based on this association. No additional incident specifics, such as confirmed breach details, data exfiltration claims, or ransom terms, are provided to maintain factual neutrality and avoid speculation. |
|||||
| Ransomware | Rohloff Group id32198 View details | South Africa | Services | ||
|
KFC Rohloff Group franchise partner Total leak: 536 GB, 103,196 Files, 30,805 Folders Data: Employees personal , Loan applications, Employees banking details, ID's, Bank account statements, Employees ACKNOWLEDGEMENT OF DEBT, RESULT OF THE DISCIPLINARY HEARING, Financial documentation for royalties, Food Cost Reconciliation and a lot of other documentation. Data type: Confidential Full publication coming soon. |
|||||
| Ransomware | Ruby Seven Studios id32193 View details | United States | IT | ||
|
Ruby Seven Studios is an organization operating within the IT sector based in the United States. The entity functions as a technology studio or service provider, though specific operational details remain limited within public threat intelligence records. It has been formally cataloged as a ransomware victim linked to the incransom threat actor group. This listing type indicates its association with a cybersecurity incident involving ransomware activity, contributing contextual data to threat-intelligence indexing efforts. The description maintains neutrality regarding unverified incident specifics, focusing solely on the documented relationship between the entity, its sector, location, and the identified threat actor. |
|||||
| Ransomware | Ruby Seven Studios id32193 View details | United States | IT | ||
|
Ruby Seven Studios Inc. https://www.rubyseven.com/ Total leak: 114 GB (123,463,823,360 bytes), 133,851 Files, 49,357 Folders. Data: Source code, Games Rules, Game assets, Game math, GDD, IGT, Analytics report Finance doc's, Royalty Reports, Tax invoice, Inventions Agreement - Employee intellectual property assignment, non competition and confidentiality agreement Personal ID/Passport, Share holders list. Data type: Confifential Partners: IGT (International Game Technology), Konami Gaming, Wazdan, Bluberi Gaming, CHAYOWO TECHNOLOGY, Everi & Aristocrat Bally's Corporation, Delaware North Gaming, Pechanga Resort & Casino, Mystic Lake Casino Hotel, Affinity Interactive, Choctaw Casinos & Resorts. Full publication coming soon. |
|||||
| Ransomware | FFKR Architects id32078 View details | United States | Manufacturing / Engineering | ||
|
FFKR Architects is a company operating within the United States, specializing in Manufacturing and Engineering sectors. The organization provides professional architectural and engineering consultancy services tailored to industrial and technical project requirements. FFKR Architects has been formally listed as a ransomware victim within the threat-intelligence index, with the associated threat actor or source identified as incransom. This listing reflects the entity's inclusion in cyber threat monitoring records tied to this specific ransomware-related activity. The description remains neutral and factual regarding the victim classification and associated actor. |
|||||
| Ransomware | FFKR Architects id32078 View details | United States | Manufacturing / Engineering | ||
|
FFKR Architects is a leading architecture and interior design firm based in Utah, with additional offices in Arizona and Idaho. They offer a wide range of services including architecture, landscape architecture, interior design, and environmental graphic design. The firm is known for its design excellence and commitment to environmental leadership, serving various sectors such as healthcare, education, hospitality, and commercial projects. With a team of over 170 professionals, FFKR empowers clients through innovative visualization techniques, ensuring informed decision-making. |
|||||
| Ransomware | el-group id32011 View details | Switzerland | null | ||
|
El-group is cataloged as a ransomware victim entity within the threat-intelligence index. Its operational context is associated with the country CH, though the specific sector remains unclassified in available data. The entity represents an organization impacted by cyber activity tied to the incransom threat actor, contributing contextual detail for analysts tracking ransomware-related incidents and associated actors. This listing type identifies el-group specifically as a ransomware victim linked to incransom. The description maintains neutrality regarding incident specifics, avoiding assumptions about data stolen, operational impact, or confirmed breach details. El-group serves as a reference point in the index for understanding ransomware victim profiles and their connections to identified threat actors. |
|||||
| Ransomware | el-group id32011 View details | Switzerland | null | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
|||||
| Ransomware | BANGKOKCABLE id31891 View details | Thailand | — | ||
|
About Bangkok Cable Bangkok Cable is Thailand's leading manufacturer of electric wires and cables, boasting over five decades of sustainable growth. The company is committed to connecting people with power and driving economic development through innovative manufacturing technologies. With a production capacity of 30,000 metric tons per year for copper and 15,000 metric tons for aluminum cables, Bangkok Cable adheres to high-quality standards and sustainable practices. Their products serve a wide range of clients, contributing to the country's development and enhancing the quality of life through reliable electrical power. |
|||||
| Ransomware | UNIPLASTICS.COM id31892 View details | United States | — | ||
|
Universal Plastics Inc. is a family-owned commercial specialty subcontractor with over 50 years of experience, specializing in custom wall panel systems, wall protection, and high-impact wall coverings. They serve a diverse clientele, including commercial projects such as airports and medical facilities, providing innovative solutions with materials like FRP, stainless steel, and plastic laminates. As a master distributor for Marlite in Northern California, they also offer a wide range of products including solid surfaces and decorative wall panels. Their commitment to quality and customer service makes them a leader in the industry. |
|||||
| Ransomware | CDGARVINLAW id31893 View details | United States | — | ||
|
CHRISTOPHER D. GARVIN (Docket #2352300) is a Wood-Ridge attorney admitted to New York State in 1990 and registered with the Office of Court Administration (OCA) of the New York State Unified Court System. Employer - CHRISTOPHER D. GARVIN, ESQ. COUNSEL AT LAW. The attorney graduated from SETON HALL UNIVERSITY. The registered office is located at 268 Valley Blvd, Wood Ridge, NJ 07075-1202, contact telephone: (201) 804-7681. Current lawyer status: registered. |
|||||
| Ransomware | EXEL id31894 View details | Canada | — | ||
|
Exel Systems Inc. specializes in providing high-quality custom heating, ventilation, and air conditioning (HVAC) and energy recovery products. Established in 1993, the company serves the institutional, commercial, and industrial markets, collaborating with building owners, consulting engineers, and contractors to deliver innovative and energy-efficient solutions. Their extensive product range and expertise enable them to handle complex projects tailored to specific client needs. Exel Systems encourages clients to explore their website for new products and application information to enhance building sustainability. |
|||||
| Ransomware | SpearFin Ltd id31824 View details | Mauritius | — | ||
|
SpearFin Ltd https://spearfin.net SpearFin offers a wide range of services including fund administration, corporate services, compliance support, and investor relations. Assets Under Administration US$10 billion. The leak occurred on June 26, 2026. Total leak: 416 GB Leak included: NDA, Correspondence Client, KYC - Passports, Certificates, Investing documents, Share Registry and Holders, Anti-Money Laundering (AML) audit, Agreements, Application forms, Bank Statements, Bank Payrolls, Loans Documents, Certificates of GBC (Global Business Company), Register of Directors and many other financial documents. Clients: YuMee Seven Six, BAMBOO BAY PRIVATE LIMITED, Asio Global Fund, 3B Capital, Abans Group, Amicorp Capital, Apex Fund Services Ltd, Pangaea Fund Limited, AL Farah Overseas Limited, Zinnia Group, AMG Services Ltd, NEO SEMI SG PTE. LTD, MIC ELECTRONICS LIMITED, Zenbridge Capital Pvt. Ltd., Zinnia Investment Advisers Pvt Ltd, Onpoint Ventures Limited, Wilson Group, Blue River, Capital Advisors Private Limited, Zenbridge Capital Pvt Ltd, Topland Group Holdings, Africa Opportunities Fund, Appollo Fund Limited and many other... Type of information: Confidential Full publication coming soon... |
|||||
| Ransomware | ssf-int.com ssf-ing.de id31825 View details | Germany | — | ||
|
SSF International GmbH is an engineering firm headquartered in Munich, Germany. A subsidiary of SSF Ingenieure AG, the company provides comprehensive engineering services in project management, supervision, consultancy, design, quality management, and special construction design worldwide. It specializes in railways, high-speed railway lines, metro and light rail, Maglev lines, and large infrastructure projects, including bridges and railway stations. The company serves international clients across various stages of project development, from early studies and design to construction, commissioning, operation, and maintenance. Its service portfolio includes BIM and GIS solutions, environmental protection, and specialized solutions for acoustic and vibration control. |
|||||
| Ransomware | nyklawfirm.com nyk.ae id31826 View details | United Arab Emirates | — | ||
|
/ |
|||||
| Ransomware | Foresee Pharmaceuticals id31822 View details | Taiwan, Province of China | — | ||
|
Foresee Pharmaceuticals Co., Ltd. https://www.foreseepharma.com Total leak: 1,2TB Leak includes: Drug Master File, ASMF, FDA/EMA, R&D, Financial statements, Clinical study reports and other confidential information. Projects: CAMCEVI, SIF, Casppian, NCE, Aderamastat, Linvemastat, FP-045, FP-016, FP-018, FP-014... Partners: Accord BioPharma, Intas Pharmaceuticals, Primevera Therapeutics, Accord Healthcare... Type of information: Confidential |
|||||
| Ransomware | SD Associates Sdn Bhd id31810 View details | Malaysia | — | ||
|
SD Associates (SDA) is a globally expanding company that prides itself in providing quality service to every client. We provide comprehensive professional project management and engineering consultancy services in diverse market segments. Our multi-disciplinary teams consisting of experienced Project Managers, Professional Engineers, Architects, Quantity surveyors, and Technical Support Managers. We are an ISO 9001, ISO 45001, and ISO 14001 certified WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information! |
|||||
| Ransomware | Third Coast Bancshares id31811 View details | United States | — | ||
|
While Third Coast Bancshares (NASDAQ:TCBX) shares continue to rise rapidly and reach new highs, its leadership is concealing one of the largest data breaches in the history of the U.S. financial sector. This situation raises serious questions about the company’s conduct. In the near future, we intend to publish a comprehensive analytical report examining the TCBX activities. The public will then have an opportunity to assess the practices carried out by the company, including violations of applicable laws and regulations, as well as the conduct of certain shareholders and business partners. Our report will also examine allegations involving individuals connected to financial-sector regulators and law enforcement. Corruption, manipulation of data, regulatory non-compliance, and the submission of potentially misleading reports represent only a small part of the concerns we intend to address. We believe the time has come to initiate short positions. Our forthcoming publications are expected to raise significant questions about the company and could have broader implications for confidence in the U.S. financial sector. As for clients and stakeholders of the financial institution, We strongly recommend that clients safeguard their funds and consider withdrawing them in the near term. Stay tuned for further updates and the release of our detailed findings. |
|||||
| Ransomware | Lansing Urgent Care id31799 View details | United States | — | ||
|
Lansing Urgent Care provides a range of urgent care services for both adults and children, including on-site medications, lab tests, and X-rays. Their facilities are designed for quick visits, with an average wait time of under one hour, and they offer telemedicine options for added convenience. The company caters to patients seeking immediate medical attention, sports physicals, and occupational health services. With multiple locations in Lansing, Okemos, and surrounding areas, they aim to deliver friendly and efficient healthcare. |
|||||
| Ransomware | Otter Tail County, Minnesota id31785 View details | United States | — | ||
|
https://ottertailcounty.gov/ |
|||||
| Ransomware | https://pacific-construction.com/ id31669 View details | United Kingdom | Construction / Real Estate | ||
|
Pacific Construction is a company operating in the construction and real estate sector, based in the United Kingdom. The company provides various services related to construction and property development. Pacific Construction was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | https://pacific-construction.com/ id31669 View details | United Kingdom | Construction / Real Estate | ||
|
project data client data contract |
|||||
| Ransomware | cambrialawfirm.com id31670 View details | Canada | — | ||
|
personal and medical cards of all clients. |
|||||
| Ransomware | clgroup id31657 View details | United States | Finance / Legal / Insurance | ||
|
CLGroup operates in the finance, legal, and insurance sector in the US, providing various services to its clients. The company's offerings cater to the needs of its customers in these sectors. CLGroup was listed as a ransomware victim associated with IncranSom. |
|||||
| Ransomware | clgroup id31657 View details | United States | Finance / Legal / Insurance | ||
|
Compunnel, founded in 1994 and headquartered in Plainsboro, New Jersey, provides information technology consulting and staffing, custom business application development, and eLearning services |
|||||
| Ransomware | gamaus.com id31652 View details | United States | IT | ||
|
Gamaus.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to clients in the US. Gamaus.com was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | gamaus.com id31652 View details | United States | IT | ||
|
https://www.zoominfo.com/c/greater-austin-merchants-cooperative-association/98978085 greater-austin-merchants-cooperative-association 400gb |
|||||
| Ransomware | BEDC.COM.AU id31599 View details | Australia | Education | ||
|
BEDC.COM.AU is an entity operating within the education sector in Australia. The organization is involved in providing educational services. BEDC.COM.AU was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | BEDC.COM.AU id31599 View details | Australia | Education | ||
|
Brighton East Dental Clinic (BEDC) is a family dental clinic dedicated to providing comprehensive dental care for families in Brighton, Caulfield, and Bentleigh. They offer a wide range of services including kids dentistry, general dentistry, cosmetic procedures, and preventative care, with a strong emphasis on patient needs and comfort. With over 30 years of experience, their team of certified dentists focuses on creating healthy, happy smiles while accepting all major health funds. The clinic is known for its convenient evening hours and commitment to emergency dental care. Employees: 50 Revenue: $5 Million Industry: Dental Practice Management Phone Number: +61 395788500 |
|||||
| Ransomware | diabetesandmetabolism.com id31600 View details | United States | Healthcare / Pharma | ||
|
Diabetesandmetabolism.com is a US-based online resource focused on diabetes and metabolism, providing information and support within the healthcare sector. The website likely offers educational content, news, and resources related to diabetes management and metabolic health. Diabetesandmetabolism.com was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | diabetesandmetabolism.com id31600 View details | United States | Healthcare / Pharma | ||
|
Diabetes and Metabolism Specialists is a specialty medical clinic located in San Antonio, TX, focused on the diagnosis and treatment of endocrine-related medical conditions. The clinic is staffed by board-certified endocrinologists, nurse practitioners, and certified diabetes educators who provide comprehensive care and education for chronic conditions such as diabetes, hyperparathyroidism, and metabolic syndrome. They emphasize professionalism and patient education, ensuring that clients understand their diagnoses and treatment options. The intended clients are individuals seeking specialized care for endocrine disorders and metabolic conditions. Employees: 50 Revenue: $5.5 Million Industry: Hospitals & Physicians Clinics Phone Number: (210) 494-3739 |
|||||
| Ransomware | stuartandassociates.com id31646 View details | United States | — | ||
|
Stuart & Associates Commercial Flooring, Inc. specializes in providing high-quality commercial flooring solutions designed to enhance customer experiences. They offer a three-year warranty on new installations when clients purchase maintenance programs, ensuring satisfaction and value throughout the process. The company features a design center with extensive product samples and emphasizes delivering projects on budget and on schedule. Their target clients include businesses seeking safe, comfortable, and aesthetically pleasing flooring options. Employees: 50 Revenue: $6.4 Million Industry: Construction Management Phone Number: (316) 267-0743 |
|||||
| Ransomware | Louisville Bar Association id31481 View details | United States | NGOs / Associations | ||
|
Loubar.org is a US-based organization operating in the NGOs and Associations sector, providing services and support to its members and community. The organization is likely focused on promoting social causes and advocating for the interests of its constituents. Loubar.org was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | Louisville Bar Association id31481 View details | United States | NGOs / Associations | ||
|
The Louisville Bar Association (LBA) provides a range of services including membership benefits, legal job placement, continuing legal education (CLE), and public service initiatives. It aims to support legal professionals at all stages of their careers while promoting diversity and community engagement within the legal field. The LBA also offers resources for individuals seeking legal representation and hosts various events and awards to recognize outstanding contributions in the legal community. Their intended clients include legal professionals, law firms, and individuals in need of legal assistance in the Louisville area. |
|||||
| Ransomware | ATMS id31462 View details | India | Other | ||
|
ATMS is an entity operating in the other sector in India, providing various services. The company is based in India and offers its services to clients. ATMS was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | ATMS id31462 View details | India | Other | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
|||||
| Ransomware | vprj.org id31352 View details | United States | NGOs / Associations | ||
|
vprj.org is a US-based organization operating in the NGOs and Associations sector. The entity provides various services and support to its members and community. vprj.org was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | vprj.org id31352 View details | United States | NGOs / Associations | ||
|
The Virginia Peninsula Regional Jail (VPRJ) is a state-authorized, regional correctional facility located in Williamsburg, Virginia, USA. Opened in 1997, VPRJ provides short-to-medium-term detention services, ensuring public safety and order across the Virginia Peninsula region under the governance of a multi-jurisdictional jail board. |
|||||
| Ransomware | lantisnet.com id31244 View details | United States | IT | ||
|
Lantisnet.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering its services to clients in the US. Lantisnet.com was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | lantisnet.com id31244 View details | United States | IT | ||
|
Lantis Enterprises, Inc. is an American consulting and management organization historically rooted in rural healthcare, skilled nursing, and senior living operations. Headquartered in Spearfish, South Dakota, the firm has expanded its focus to cross-industry advisory services |
|||||
| Ransomware | Loyalist College id31243 View details | Canada | Education | ||
|
Loyalist College is a public college located in Belleville, Ontario, Canada, offering a range of programs in fields such as business, health sciences, and technology. The college provides education and training to students in the Canadian province of Ontario. Loyalist College was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | Loyalist College id31243 View details | Canada | Education | ||
|
The management of this institution was repeatedly warned about the disclosure of hundreds of personal data. Each of you who is faced with the consequences of the leak can be absolutely sure that the management of Loyalist College absolutely does not care about its students, employees and partners. ------------------------- Loyalist is Ontario's Destination College, empowering students, faculty, staff, and partners through experiential, industry cluster-based education, training and applied research programs. The College provides job-ready graduates for, and knowledge transfer to, industry and the community. |
|||||
| Ransomware | TRULITE GLASS & ALUMINUM SOLUTIONS id31240 View details | United States | Manufacturing / Engineering | ||
|
TRULITE GLASS & ALUMINUM SOLUTIONS is a US-based company operating in the manufacturing and engineering sector, offering glass and aluminum solutions. The company provides various products and services to its customers. TRULITE GLASS & ALUMINUM SOLUTIONS was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | TRULITE GLASS & ALUMINUM SOLUTIONS id31240 View details | United States | Manufacturing / Engineering | ||
|
TRULITE GLASS & ALUMINUM SOLUTIONS Date: August 2026 Overview Trulite Glass & Aluminum Solutions, a portfolio company of Truelink Capital (Los Angeles, CA), is a leading North American fabricator and distributor of architectural glass and aluminum systems. Headquartered in Alpharetta, Georgia, the company operates 40+ fabrication and distribution facilities across the United States and Canada, serving the commercial construction industry. Trulite was founded in 1978 and has undergone significant expansion through acquisitions — including Vitro America, Western States Glass, AGC Fabrication, Super Sky Products, American Insulated Glass, and others. In October 2022, Truelink Capital acquired Trulite from Sun Capital Partners. The company generates estimated annual revenue of $800M–$1.2B and employs 2,000–3,500 people. Incident We have obtained full and unrestricted access to Trulite's internal infrastructure. The total volume of exfiltrated data exceeds 8 terabytes. Data in Our Possession The dataset includes but is not limited to: - Complete corporate databases — ERP system (Microsoft Dynamics AX), CRM, operational databases - Financial records — multi-year Profit & Loss statements by branch, EBITDA schedules, debt covenant compliance calculations, 13-week cash flow forecasts, weekly and monthly financial reporting packages prepared for private equity ownership - M&A documentation — Confidential Information Memorandums (CIM), executed Stock Purchase Agreements, acquisition pipeline documents, due diligence materials, corporate structure charts with ownership percentages - Private equity communications — internal correspondence and reporting between Trulite management and fund ownership (Sun Capital Partners, Truelink Capital) - Board of Directors materials — governance records, board presentations, strategic planning documents - HR and employee data — personnel records, payroll, benefits information - Customer and vendor data — contracts, pricing agreements, project documentation, accounts receivable/payable - IT infrastructure documentation — network architecture, system configurations, credentials - Operational data — production records, logistics, fleet management, facility documentation across all 40+ locations Proof of Access Sample data will be published to confirm the scope and authenticity of the breach. Full data publication will follow if no resolution is reached. Contact The Trulite management team has been contacted directly and provided with instructions to initiate private negotiations. A deadline has been communicated. This is the only public statement at this time. Further updates — including data samples — will follow according to the established timeline. |
|||||
| Ransomware | pushidrosal.id id31201 View details | Indonesia | Other | ||
|
Pushidrosal.id is an entity based in Indonesia, operating in the other sector. The entity's specific offerings are not well-documented, but it is known to be located in the country of Indonesia. Pushidrosal.id was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | pushidrosal.id id31201 View details | Indonesia | Other | ||
|
* |
|||||
| Ransomware | lccgroup.com id31202 View details | Philippines | Construction / Real Estate | ||
|
LCC Group is a Philippines-based company operating in the construction and real estate sector, offering various services to its clients. The company is involved in development and management of properties. LCC Group was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | lccgroup.com id31202 View details | Philippines | Construction / Real Estate | ||
|
LCC - Liberty Commercial Center, Inc is one of the pioneering retail establishments in the Bicol Region. Based in the dynamic province of Albay, LCC primarily operates supermarkets, department stores, malls, and food establishments. LCC is also engaged in property development. Banking on the cherished Filipino trait of hospitality, LCC's corporate tagline - The company's Best For You empowers its stakeholders and corps of new - generation and seasoned managers to commit themselves to a market stewardship that puts a high premium on rewarding LCC customers for their loyalty and patronage. LCC's growth is rooted in the Filipino spirit of entrepreneurship as an agent of change and progress. Over 75 years of retailing knowhow and quality service continue to touch the lives of its Bicolano consumers and their communities www.lcc.com.ph |
|||||
| Ransomware | https://geleximco.vn/ id31203 View details | Viet Nam | Manufacturing / Engineering | ||
|
Geleximco is a Vietnam-based company operating in the manufacturing and engineering sector, providing various products and services. The company is involved in multiple industries, including construction and infrastructure development. Geleximco was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | https://geleximco.vn/ id31203 View details | Viet Nam | Manufacturing / Engineering | ||
|
200gb data |
|||||
| Ransomware | clintonhealthaccess.org id31200 View details | United States | NGOs / Associations | ||
|
Clinton Health Access Initiative is a US-based non-governmental organization operating in the healthcare sector, providing access to medicines and health services. The organization works to improve healthcare systems in various countries. Clinton Health Access Initiative was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | clintonhealthaccess.org id31200 View details | United States | NGOs / Associations | ||
|
This Clinton foundation sponsors the sterilization of women in Africa and South America. With the help of this foundation, organs harvested criminally by transplant surgeons from people in Third World countries are legalized to improve the quality of life of the rich in capitalist countries, including the United States. We have irrefutable evidence of their secret accounts, including transactions in cryptocurrency, from which transplanted organs were purchased to replace Bill Clinton's wife, Hillary Clinton. |
|||||
| Ransomware | Oleoductos del Valle id31199 View details | Argentina | Energy | ||
|
Oleoductos del Valle is an energy sector company based in Argentina, involved in the transportation of oil and related energy products. The company operates in the energy sector, providing essential services in Argentina. Oleoductos del Valle was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | Oleoductos del Valle id31199 View details | Argentina | Energy | ||
|
During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include: 1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severance calculations and compensation agreements. 2.Financial and regulatory reports filed with CNV and BYMA, including documents related to rating agencies (Moody's) and internal shareholder agreements. 3.Tax declarations and reports submitted to AFIP (Sicore, Ganancias, DDJJ IVA). 4.Documents related to tariff policy and SEN interactions, including WACC and TIR calculations used in tariff reviews. 5.Incident reports and environmental documentation, including reports on spills in Catriel and Medanito, as well as Rosen OSSR technical reports on pipeline conditions. 6.Confidentiality agreements with key partners, including Halliburton, Horizon, YPF, Otasa, McKinsey, and KPMG. 7.Internal whistleblower channel materials (Ley 27.401), including internal complaints and compliance reports. 8.Documents related to dividend payments and banking transactions. 9.Personal data of directors, candidates, and key employees, including ID numbers and CVs. |
|||||
| Ransomware | ecfa.org id31167 View details | United States | NGOs / Associations | ||
|
The Evangelical Council for Financial Accountability (ECFA) is a US-based nonprofit organization that provides accreditation to Christian ministries and churches, promoting financial transparency and accountability. ECFA offers resources and training to its members, aiming to enhance their financial management and governance practices. Ecfa.org is listed as a ransomware victim associated with incransom |
|||||
| Ransomware | ecfa.org id31167 View details | United States | NGOs / Associations | ||
|
The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in collective revenue. |
|||||
| Ransomware | quantinuum.com id31147 View details | United States | IT | ||
|
Quantinuum.com is a US-based company operating in the IT sector, providing various technology solutions. As a leading entity in its field, it offers innovative services to its clients. Quantinuum.com was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | quantinuum.com id31147 View details | United States | IT | ||
|
Quantinuum is a quantum computing company that develops advanced quantum computers, software, and cybersecurity solutions to solve complex scientific and industrial challenges. The company provides full-stack quantum technologies for areas such as materials science, drug discovery, encryption, artificial intelligence, and optimization, helping enterprises and researchers accelerate innovation through quantum computing. The leak dates back to pre-IPO. QUANTINUUM deliberately withheld this information from investors. The exact amount of stolen data will be revealed after publishing. |
|||||
| Ransomware | PARTNERED HEALTH GROUP id31063 View details | Australia | Healthcare / Pharma | ||
|
PARTNERED HEALTH GROUP is a healthcare organization based in Australia, operating within the healthcare and pharmaceutical sector. The group likely provides medical services and support to patients and healthcare providers. PARTNERED HEALTH GROUP was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | PARTNERED HEALTH GROUP id31063 View details | Australia | Healthcare / Pharma | ||
|
PARTNERED HEALTH GROUP — Australia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Industry: Healthcare — Primary Care, Occupational Health, Psychology, Telehealth Headquarters: Australia (NSW, QLD, VIC, WA, ACT) Owner: Quadrant Private Equity Clinics: 60+ nationwide Brands: Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, TeleWell Website: partneredhealth.com.au PENDING ACQUISITION: Bupa — ~$450,000,000 AUD Announced July 2, 2026 (Australian Financial Review) ACCC and FIRB regulatory approval pending. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ BREACH SUMMARY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Date of access: 23 June 2026 Data exfiltrated: 3.2 TB Total files: 2,298,203 Servers accessed: 21 (9 AD Controllers + 11 Best Practice Medical Servers + 1 Central SQL Server) SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf, VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups Clinics compromised: 21 locations across 5 states/territories Patient records: 17,727+ named patient files identified Staff HR files: Full employee records including passports, AHPRA registrations, tax declarations Period of data: 1999 — 2026 (27 years) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHAT WE HAVE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ▪ Complete patient medical records from 21 GP clinics — consultation notes, referral letters, pathology results, diagnostic imaging reports, prescriptions ▪ Full SQL database dumps — ZedMed (patient management), Payroll (all staff salaries), DocPays (doctor payments), VectraplexECG (cardiac/ECG monitoring data) ▪ 11 complete Best Practice patient database backups — one per clinic — including BPSPatients, BPSDocuments (up to 48 document partitions per clinic) ▪ Staff HR files — employment contracts, passport scans, AHPRA medical registrations, tax file declarations, superannuation details, performance reviews ▪ Bupa corporate data — direct billing agreements, fund tables for all Australian states, patient invoices, corporate program documents (Bronze/Silver/Gold), and active Bupa web portal session cookies ▪ Financial records — QuickBooks databases (2004-2026), Medicare billing, DVA remittances, private health fund claims ▪ Clinical governance — full RACGP accreditation files, patient consent templates, internal clinical audit data ▪ 27 years of accumulated medical data (1999-2026) across ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health was given the opportunity to resolve this matter privately and protect patient data. Instead of acting in the interest of their patients, they spent 22 days in silence, hired lawyers, and obtained a court injunction that has no practical effect outside Australian jurisdiction. Their public statement of July 15 describes the breach as affecting "some" data from "some" clinics. This is misleading. The reality: 3.2 terabytes. 2.3 million files. 21 servers. 27 years of patient medical history. Every clinic server in their network was accessed. Complete SQL database dumps were taken including the central patient management system and payroll for every employee. And critically — the data includes Bupa's own corporate information: billing agreements, fund pricing tables for every Australian state, named patient invoices, and active browser session cookies from Bupa's login, corporate, and web portals. We understand this acquisition matters. $450 million is a significant transaction. A full data publication would create material regulatory complications with the ACCC and FIRB review process. We trust the board and advisors at Quadrant understand what that means. This is not a threat. This is a deadline. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ DEADLINE: [DATE + 10 DAYS] ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health has 10 days to resume negotiations and reach a settlement. If no agreement is reached: Stage 1 — Complete file tree listing (2.3M files) + all HR/staff records published Stage 2 — SQL databases (ZedMed, Payroll, ECG) released for download Stage 3 — Bupa corporate data, fund tables, billing agreements, session data published. ACCC, FIRB, and Bupa executive leadership notified directly. Stage 4 — Full 3.2 TB data dump made available for public download. |
|||||
| Ransomware | sslf.local id31059 View details | United States | Other | ||
|
sslf.local is an entity operating in the other sector, located in the United States. The entity's specific offerings are not well-documented, but it is known to be part of the other sector. sslf.local was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | sslf.local id31059 View details | United States | Other | ||
|
Samuels & Thornton is a law firm based in New Orleans, specializing in medical malpractice and personal injury cases. They provide personalized legal guidance to individuals, families, and businesses facing legal challenges, ensuring that each client receives dedicated attention from experienced attorneys. Their practice areas include medical malpractice, product liability, auto accident litigation, and more. The firm is committed to delivering proven results and effective representation throughout Louisiana. |
|||||
| Ransomware | harwal.net id31028 View details | United Arab Emirates | Manufacturing / Engineering | ||
|
Harwal.net operates within the manufacturing and engineering sector, primarily based in the United Arab Emirates. The company likely provides various services and products related to its sector. Harwal.net was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | harwal.net id31028 View details | United Arab Emirates | Manufacturing / Engineering | ||
|
Harwal.net Harwal Group is the largest plastics recycler in the Middle East, founded in 1938, with an annual processing capacity of over 200,000 tons of plastics and metals. Manufacturing includes construction materials, pre-engineered building systems, industrial packaging, consumer goods, and refrigeration equipment, including commercial chillers and freezers under the Celsius brand. Companies within the group: four main divisions — TSSC, Interplast, Cosmoplast, and Intermetal — unite 28 business units operating in 65 countries worldwide. DATA- 12tb |
|||||
| Ransomware | https://eclmn.com/ id31010 View details | United States | IT | ||
|
Eclmn is an IT company based in the United States, offering various services within the information technology sector. The company operates in the US, providing IT solutions to its clients. Eclmn was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | https://eclmn.com/ id31010 View details | United States | IT | ||
|
A family-run health and residential care organization in Minnesota. They provide adapted housing, professional in-home support, and daily living solutions for adults with physical disabilities and limited mobility |
|||||
| Ransomware | Della Casa Group AG id31009 View details | Switzerland | Construction / Real Estate | ||
|
Della Casa Group AG is a Swiss-based company operating in the construction and real estate sector, providing various services and offerings to its clients. The company is involved in development, construction, and management of properties in Switzerland. Della Casa Group AG was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | Della Casa Group AG id31009 View details | Switzerland | Construction / Real Estate | ||
|
041 785 61 31 / 041 785 61 46 / [email protected] 041 785 61 36 / [email protected] 041 785 61 30 / [email protected] 041 785 61 33 / [email protected] 041 785 61 43 / [email protected] 041 785 61 42 / [email protected] *************************************************** (240,391,913,425 bytes) 86,332 Files, / 15,359 Folders Personal / Client Information Accounting / Finance Details of current and future projects Other |
|||||
| Ransomware | minigrip.com.mx id31005 View details | Mexico | Manufacturing / Engineering | ||
|
Minigrip.com.mx is a Mexico-based company operating in the manufacturing and engineering sector, providing various products and services. The company's offerings cater to a range of industries, leveraging its expertise in manufacturing and engineering. Minigrip.com.mx was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | minigrip.com.mx id31005 View details | Mexico | Manufacturing / Engineering | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
|||||
| Ransomware | DUCON id31001 View details | Colombia | Other | ||
|
DUCON is a company based in Colombia, operating in the other sector. The company provides various offerings, but specific details are not available. DUCON was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | DUCON id31001 View details | Colombia | Other | ||
|
Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation. |
|||||
| Ransomware | greenecountyga.gov id31002 View details | United States | Public Sector | ||
|
Greenecountyga.gov is a government website serving Greene County in the state of Georgia, US, providing public services and information to its residents. As a public sector entity, it offers various services and resources, including county administration, law enforcement, and community development. Greenecountyga.gov was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | greenecountyga.gov id31002 View details | United States | Public Sector | ||
|
Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is widely known for its combination of rural heritage, historic architecture, and upscale resort living centered around Lake Oconee. |
|||||
| Ransomware | foundationstofreedom.org id31003 View details | United States | NGOs / Associations | ||
|
Foundationstofreedom.org is a US-based non-governmental organization operating in the sector of NGOs and associations. The entity provides various offerings to support its mission. Foundationstofreedom.org was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | foundationstofreedom.org id31003 View details | United States | NGOs / Associations | ||
|
Foundations to Freedom is a US-registered 501(c)(3) non-profit organization that provides recovery housing, social adaptation programs, and comprehensive therapeutic support for individuals overcoming alcohol and substance abuse, as well as survivors of domestic violence.The organization is dedicated to offering a safe, structured environment for individuals to rebuild their lives from the ground up and maintain long-term sobriety. It is headquartered in DeLand, Florida, USA |
|||||
| Ransomware | takethehop.com id30944 View details | United States | Retail / E-commerce | ||
|
Takethehop.com operates in the retail and e-commerce sector, providing online shopping experiences to customers in the United States. As an e-commerce platform, it offers various products and services to its customers. Takethehop.com was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | takethehop.com id30944 View details | United States | Retail / E-commerce | ||
|
The HOP, an American regional public transit system operated by the Hill Country Transit District (HCTD). Founded in the 1960s in the state of Texas (USA) as a voluntary transportation service, the organization has grown over the decades into a major public public-transport network. |
|||||
| Ransomware | healthlawadvocates.org id30860 View details | United States | NGOs / Associations | ||
|
Health Law Advocates is a non-profit organization based in the United States, operating in the sector of NGOs and associations, providing advocacy services related to health law. The organization is focused on promoting access to healthcare and advocating for the rights of individuals in the healthcare system. Health Law Advocates was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | healthlawadvocates.org id30860 View details | United States | NGOs / Associations | ||
|
Health Law Advocates (HLA), an American non-profit, public interest law firm based in Boston, Massachusetts. Founded in 1996, HLA provides free (pro bono) legal representation to low-income residents and vulnerable populations who face barriers to accessing or paying for healthcare. |
|||||
| Ransomware | autismuslink.ch id30818 View details | Switzerland | NGOs / Associations | ||
|
Autismuslink.ch is a Swiss non-governmental organization that operates in the sector of NGOs and associations, providing support and resources for individuals with autism. Located in Switzerland, the organization offers various services and initiatives to promote awareness and inclusion. Autismuslink.ch was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | autismuslink.ch id30818 View details | Switzerland | NGOs / Associations | ||
|
The Stiftung Autismuslink (Autism Link Foundation), a Switzerland-based competence center dedicated to supporting adolescents and young adults with Autism Spectrum Disorder (ASD). Headquartered in Bern, the organization focuses on helping individuals with autism achieve social and professional integration. |
|||||
| Ransomware | cabincreekhealth.com id30816 View details | United States | Healthcare / Pharma | ||
|
Cabincreekhealth.com is a healthcare organization based in the United States, operating in the medicine sector. The entity provides various healthcare services to its patients. Cabincreekhealth.com was listed as a ransomware victim associated with incransom |
|||||
| Ransomware | cabincreekhealth.com id30816 View details | United States | Healthcare / Pharma | ||
|
Cabin Creek Health Systems (CCHS), a non-profit community healthcare organization founded in 1973 by coal miners in West Virginia. It operates as a Federally Qualified Health Center (FQHC), providing comprehensive medical services to rural and urban residents across Kanawha County |
|||||