Ransomware victim disclosure
← All victimsJRT Mechanical
Claimed by Akira · listed 3 days ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Manufacturing
- Listed on leak site
- Aug 28, 2026
About the victim
AI dossier — public-source company profileJRT Mechanical is a full-service mechanical contractor specializing in plumbing, HVAC, hydronics, and mechanical insulation. Founded in 1992, the company has grown to over 160 employees and focuses on commercial and industrial projects in the Pacific Northwest.
- Industry
- Mechanical Contracting (Plumbing, HVAC, Hydronic Systems)
- Employees
- 160
- Founded
- 1992
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated sensitive data including employee PII (SSNs, passports, driver's licenses), medical information, and financial records across a 46 GB dataset.The Akira group claims to have exfiltrated approximately 46 GB of corporate data, including detailed employee personal information (SSNs, passports, driver's licenses, resumes), medical records, client information, project details, financial records, confidential files, contracts, agreements, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (SSNs, passports, driver's licenses)
- Employee resumes and documents
- Medical information
- Client information
- Project details
- Financial records
- Confidential files
- Contracts and agreements
- NDAs
What the group claims
JRT Mechanical is a full-service mechanical contractor specializing in plumbing, HVAC, hydronic s, and mechanical insulation, serving the Pacific Northwest for over 30 years. Founded in 1992, the company has expanded from a small plumbing business to a robust team of over 160 employees , focusing primarily on commercial and industrial projects. We will upload 46gb of corporate data soon. Detailed employee personal information (SSNs, passp orts, DLs, resumes, and another personal docs scans), medical information, client information, projects, financials, confidential files, contrast and agreements, NDAs and so on.
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

