Ransomware victim disclosure
← All victimsWentworth, Inc.
listed as Wentworth · Claimed by genesis · listed 4 days ago
Status timeline
- Listed
May 30, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileWentworth, Inc. is a home remodeling company operating in the Washington, DC metropolitan area, including Montgomery County, Maryland and Northern Virginia. They provide residential renovation and remodeling services to clients across the region.
- Industry
- Home Remodeling & Construction
- Address
- Washington, DC / Montgomery County, Maryland / Northern Virginia
Attack summary
Severity: high — Confirmed exfiltration of 1.5 TB spanning financial data, operational records, email archives, and user files; no encryption mentioned but data publication disclosed. Scale and sensitivity of financial and operational data elevates this above medium.The Genesis group claims to have exfiltrated approximately 1.5 TB of data from Wentworth's systems, including project files, operational data, financial records, email archives, and network user folders. No encryption-based attack is mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- Project data
- Operational data
- Financial data
- Email archives
- Network user folders
- Company fileserver contents
What the group claims
the DC Metro area's premier design-build firm
The leak post
captured from the group's siteWentworth, Inc. is a home remodeling company serving Washington, DC and the surrounding areas in Montgomery County, Maryland and Northern Virginia. ``` - 1.5 Tb of accessible data. - Project Data - Operational Data. - Financial Data. - Data from company fileserver. - Email archives. - Folders of network users. ``` [Download The List of Company Files](http://genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion/download/e21f3327f23dba31d2a6.txt)
Screenshot of the leak post

Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
