Ransomware victim disclosure
← All victimsIDS
listed as ids-michigan.com · Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedMay 4, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- May 4, 2024
About the victim
AI dossier — public-source company profileIDS is a fully integrated architecture, engineering, interiors, and technology firm based in Troy, Michigan. They specialize in design services spanning architecture, engineering, interior design, technology integration, energy, and sustainability consulting.
- Industry
- Architecture, Engineering & Design Services
- Address
- 1441 W Long Lake Rd, Suite 200, Troy, MI 48098, USA
Attack summary
Severity: high — Confirmed exfiltration of large dataset (~550GB) including CAD/design files, corporate data, and credentials; data published by the group. Significant business impact for professional services firm.BlackBasta claims to have exfiltrated approximately 550GB of data from IDS, including project files, CAD drawings, user credentials, and corporate data. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Project files
- CAD drawings
- User credentials
- Corporate data
- Technology/system information
What the group claims
IDS fully integrated firm specializing in architecture, engineering, interiors, technology, energy & sustainability.SITE: www.ids-michigan.com Address : 1441 W Long Lake Rd, Suite 200, Troy, MI 48098 USAALL DATA SIZE: ~550gb+ 1. Projects 2. CAD and drawings 3. Users, Corporate data & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

