Ransomware victim disclosure
← All victimsNorthwest Woodworks
Claimed by akira · listed 4 days ago
Status timeline
- Listed
May 27, 2026
- Data leaked
At a glance
- Group
- akira
- Status
- Data leaked
- Sector
- Manufacturing
- Listed on leak site
- May 27, 2026
About the victim
AI dossier — public-source company profileNorthwest Woodworks is a custom cabinetry and architectural woodwork manufacturer serving commercial clients for over 30 years. They provide design and fabrication services for commercial spaces, combining technology with skilled craftsmanship.
- Industry
- Custom Cabinetry & Architectural Woodwork
Attack summary
Severity: critical — Confirmed exfiltration of regulated personal data at scale (SSNs, passports, driver's licenses) and sensitive business data (financials, client information, confidential drawings). Data publication already announced.The Akira group claims to have exfiltrated 31 GB of corporate data including employee personal identification documents, financial records, client information, and confidential design drawings. The group has announced intent to publish the data.
Data the group says was taken
AI dossier — extracted from the leak post- Employee identification documents (passports, driver's licenses)
- Social Security Numbers
- Employee personal information
- Financial records
- Client information
- Confidential architectural drawings
- Contracts and agreements
- NDAs
What the group claims
Northwest Woodworks is a trusted partner of contractors for over 30 years, specializing in cust om cabinets and architectural woodwork for various commercial spaces. They combine cutting-edge technology with skilled craftsmanship to create cost-effective solutions that bring clients' v isions to life. We will upload 31gb of corporate data soon. Employee personal information (passports, DLs, SSNs and other information), contracts and agreements, financials, clients information, confidentia l drawings, NDAs, etc.
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
