Ransomware victim disclosure
← All victimsCavalier Flooring Systems Inc.
Claimed by genesis · listed 4 days ago
Status timeline
- Listed
May 30, 2026
- Data leaked
At a glance
- Group
- genesis
- Status
- Data leaked
- Country
- US
- Sector
- Manufacturing
- Listed on leak site
- May 30, 2026
About the victim
AI dossier — public-source company profileCavalier Flooring Systems Inc. is a commercial flooring and tile contractor based in Richmond, VA, serving corporate, healthcare, hospitality, retail, government, and other institutional markets across the region. They offer installation, concrete services, and flooring material sales.
- Industry
- Commercial Flooring & Tile Contracting
- Address
- Richmond, VA, United States
Attack summary
Severity: high — Confirmed exfiltration of 1.5 TB of significant business data including contracts, NDAs, customer/project information, and employee network folders. Data has been published with download link, indicating operational disclosure and potential exposure of sensitive business and personal information.Genesis claims to have exfiltrated 1.5 TB of data from Cavalier Flooring Systems, including project data, sales records, network user folders, contracts, NDAs, and company fileserver contents. The group has published the breach and made data available for download.
Data the group says was taken
AI dossier — extracted from the leak post- Project data
- Sales data
- Network user folders
- Contracts
- NDAs
- Company fileserver contents
What the group claims
A flooring and tile contractor
The leak post
captured from the group's siteCavalier Flooring Systems Inc. is a flooring and tile contractor based in Richmond. ``` - 1.5 TB of accessible data. - Project data. - Sales data. - Network users folders. - Contracts and NDA's. - Data from company fileserver. ``` [Download The List of Company Files](http://genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion/download/f10ce733580c413f2c3a.txt)
Screenshot of the leak post

Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
