Ransomware victim disclosure
← All victimssierralobo.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedMar 12, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 12, 2024
About the victim
AI dossier — public-source company profileSierra Lobo, Inc. is an established aerospace and defense contractor with 32+ years of experience providing test, evaluation, engineering, and R&D services. The company operates multiple engineering centers nationwide, including the Technology Development and Engineering Center (TDEC) in northern Ohio, and serves NASA, the Department of Defense, and commercial aerospace customers.
- Industry
- Aerospace & Defense Engineering Services
- Address
- 102 Pinnacle Drive, Fremont, OH 43420, US
- Founded
- 1992
Attack summary
Severity: critical — Exfiltration of sensitive data from a US government contractor (NASA, DoD) including employee PII, payroll, and potentially classified/controlled technical information. Large data volume (1.5 TB) and confirmed publication elevate to critical.BlackBasta claims to have exfiltrated approximately 1.5 TB of data from Sierra Lobo, including accounting records, employee personal documents, payroll information, and project files. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- accounting records
- employee personal documents
- payroll data
- project files
- engineering/technical data
What the group claims
Sierra Lobo, Inc. specializes in providing test, evaluation and engineering services to the aerospace sector nationwide. We also offer in-house engineering and R&D services through our Technology Development and Engineering Center (TDEC) in northern Ohio.SITE: www.sierralobo.com Address : 102 Pinnacle Drive Fremont, OH 43420 USALL DATA SIZE: ~1.5tb 1. Accounting 2. Personal employees documents 3. Payroll 4. Projects and much more…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

