Home All Victims John Engel Team

John Engel Team

ShadowByt3$

This record tracks a ransomware attack claimed by the ShadowByt3$ group against John Engel Team. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.

Window Zero

EXPOSURE GAP

Window Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.

0days open
t1 · Published t2 · Pending
Sep 10, 2026Not disclosed yet
Business Category
Services
Employees
51-100
Discovered
2026-09-10
Published
September 10, 2026
Disclosed / Notified
Not disclosed yet
Victim ID
vheCFvqoa8r9

Attack Summary

Contact us and negotiate. Don't be like the other real estate companies we have breached. We have serious data which contains the following below. Also we have a image url too to show you that we are not bluffing negotiate and we will remove your name and show you all the proof you want. url: http://sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion/invoice.png Data Compromised: the leak contains 0.014 million contacts (exactly 14,476 unique customer records). The following was stolen 1. Complete Identity and Client Databases (14,476 Total Profiles) The extraction completely drains the brokerage team's customer network, divided into three distinct lifecycle tables: - 10,993 Nurtured Contacts: - 3,306 Archived Contacts: - 177 Awaiting Nurture Contacts: The fresh pipeline of new inquiries, open-house visitors, and active 30-day leads. 2. Deep Behavioral Tracking & Psychological Analytics For every single one of those 14,476 profiles, We stole exact behavioral history and intent metrics, including: - Predictive Intent Metrics: scout score and score change counters that signal exactly when a high-net-worth client is getting ready to purchase. - Direct Interaction Metrics: Explicit lists of Homes Viewed, Homes Interested (properties starred or liked), Home Value Alert Views, and Market Activity Alert Views. - Communication Analytics: Logs of Email receives, Email opens, email clicks, email rejects, and system Errors mapping out exactly how responsive a customer is to digital alerts. 3. Corporate Financial and Transaction Data - 40 Invoice PDFs: A localized batch of billing records detailing contractual pricing, vendor relationships, and enterprise account balances. - Corporate Payment Method: Active account billing profiles, explicitly exposing a corporate Visa card ending in 8265 with an expiration date of 01/29. 4. Direct Brand Impersonation Assets - Administrative Access Details: The team leader’s personal profile details, including name, primary corporate emails ([email protected], [email protected]), direct contact phone numbers (203 247 4700), and official state real estate license number (RES.0787476). - High-Definition Media Links: Pristine branding paths hosted on the platform's live AWS CloudFront CDN network (d1buiexcd5gara.cloudfront.net - Operational Templates: The exact welcoming and onboarding text strings used by the agents to register new users. The .csv is in the format below: Nurtured_Contacts Name,Email,scout score,score change,type,tags,created at,Auto Nurture Active,Alerts,Email receives,Email opens,email rejects,email clicks,Homes Viewed,Homes Interested,Home Value Alert Views,Market Activity Alert Views,Errors,Starred and that is for all of them. If you don't negotiate we will sell it on underground forums for one person only and we will send proofs to bleepingcomputer and haveibeenpwned. You have 72 hours to negotiate it will get leaked on 09/12/2026 at 10:10 PM New York Time EST/EDT. To negotiate are session is below for negotiations only session: 05dd14d0860cb5d6901de01af2a84c026d914197d0f8ed892085ea3be556563301 contact us via email has a second option: [email protected]

Leak Screenshots

2 CAPTURED

Captured directly from the operator's leak site by our collector.

Proof files published by the operator — 1 image(s) harvested from this entry. Content is locked; type and dimensions shown.

No text found
Showing the latest capture only
Unlock the daily capture history — up to 45 days of evidence, plus the 1 proof file(s) the operator published.

Dark Web Exposure

Cross-referenced against HaveIBeenRansom's dark-web index of ransomware leaks, breaches & infostealer logs.
0
found in Infostealer logs
0
found in Traditional breaches
0
found in Ransomware leaks
Emails exposed
••••
Internal
•••
External
•••
Distinct leaks
••
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
Full exposure is locked
See every breached email, the internal-vs-external split and each leak source behind this victim.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this victim →
Visit Website Original Post View Group: ShadowByt3$
Legal Disclaimer: This ransomware victim record reflects information published on the operator's leak site. Breach.house only records what the operators themselves publish in the open. We take screenshots of their public pages and keep the proof material they post there, so that a listing can be verified and its status tracked over time. We do not purchase data, we do not solicit or encourage its publication, we do not access any private system, and we do not alter anything we record. Nothing is offered for download here, and detailed content is not published on this page or anywhere else on the public site: access to it is restricted to vetted customers under contract, for incident response, due diligence and cyber-resilience work. Breach.house is not affiliated with, and does not act on behalf of, the operators who publish this material. If you represent an organisation or individual named here and want a record reviewed or removed, contact us and we will act on it.