Ransomware victim disclosure
← All victimsCRI Electric
Claimed by Rhysida · listed 2 hours ago
Status timeline
- ListedAug 25, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Aug 25, 2026
- Data size
- 5.79 TB
- Records
- 151 vendor W-9 forms
About the victim
AI dossier — public-source company profileCRI Electric is a veteran-owned electrical services company based in San Antonio, Texas, founded in 1998. They provide residential and commercial electrical services including emergency repairs, EV charger installations, and home rewiring, and hold SDVOSB (Service-Disabled Veteran-Owned Small Business) certification.
- Industry
- Electrical Services & Contracting
- Address
- San Antonio, Texas, US
- Employees
- ~600
- Founded
- 1998
Attack summary
Severity: critical — Exfiltration of regulated data at scale: federal employee credentials including VA identity and DoD access artifacts, employee SSNs/bank account information, medical records, healthcare data, and classified/confidential government documents (GI-Confidential folders). Exposure of sensitive national security-related credentials and DoD contract payment systems poses significant operational and security risk.Rhysida claims to have exfiltrated 5.79 TB of data from CRI Electric, including employee federal account artifacts, payroll records with SSNs, HR files, DoD-related credentials and contract payment information, public-sector bid pricing documents, corporate records, and financial data. The group is offering the stolen data for sale with a stated 7-day auction window.
Data the group says was taken
AI dossier — extracted from the leak post- Employee federal credentials (Login.gov, DoD DS Logon, ID.me)
- TSP (retirement savings) account data
- 151 vendor W-9 forms with SSNs/EINs
- Payroll documents and HR correspondence
- OSHA injury/incident reports with photos
- Public-sector bid pricing (SAWS, SAISD, NISD)
- SDVOSB certification and corporate bylaws
- QuickBooks financial records
- 16,389 unique email addresses
- 11,963 phone numbers
- 12,076 individuals with names and addresses
- 148 IBANs
- Login credentials (5,941 files)
- Medical/health insurance data (2,738 files)
What the group claims
Veteran-owned electrical services business based in San Antonio, providing residential and commercial electrical services since 1998.
The leak post
captured from the group's siteCRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial clients, offering services such as emergency electrical repairs, EV charger installations, and home rewiring. **We are pleased to present:** Employee's federal account artifacts** (`HR-Confidential\Israel's Forms`): Login.gov personal recovery key (VA identity), TSP (retirement savings), ID.me, DoD DS Logon, PIEE (DoD contract payments)151 vendor W-9 forms** (SSN/EIN), payroll docs, HR-lawyer (privileged) correspondence, OSHA-adjacent injury/incident reports with photos.Public-sector bid pricing** (2025�2026: SAWS HQ EV charging, SAISD, NISD) � bid-competitiveness and Davis-Bacon certified-payroll context.Corporate docs (SDVOSB certification, Articles, bylaws, stock ledgers), QuickBooks financials, a Power of Attorney With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, l…
Data the group says was taken
- employee federal account artifacts
- W-9 forms with SSN/EIN
- payroll documents
- HR and legal correspondence
- OSHA injury/incident reports
- public-sector bid pricing
- corporate documents
- QuickBooks financials
- Power of Attorney
- SDVOSB certification
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

