Ransomware victim disclosure
← All victimsSpray Equipment & Service Center
Claimed by Akira · listed 6 days ago
Status timeline
- ListedJun 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Business Services
- Listed on leak site
- Jun 9, 2026
About the victim
AI dossier — public-source company profileSpray Equipment & Service Center is a provider of consultation, turnkey industrial finishing equipment, and training services for coating applications. They serve clients seeking efficient coating solutions to enhance product quality and streamline production processes.
- Industry
- Industrial Equipment & Coating Services
Attack summary
Severity: high — Confirmed exfiltration of 26 GB including regulated PII (driver's licenses, W-9 forms with SSNs), financial records, and proprietary business data (drawings, contracts, projects). Data has been published.The Akira group claims to have exfiltrated approximately 26 GB of corporate data, including employee personal information (driver's licenses, W-9 forms), financial records, contracts, project information, technical drawings, and partner data. Publication of this data is stated as forthcoming.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal information (driver's licenses)
- W-9 tax forms
- financial records
- contracts
- project information
- technical drawings
- partner information
What the group claims
Spray Equipment & Service Center is a leading provider of consultation, turnkey industrial fini shing equipment, and training services for coating applications. They cater to clients seeking efficient and high-performance coating solutions, enhancing product quality and streamlining pr oduction processes. We will upload 26gb of corporate data soon. Employee personal information (DLs, w-9 forms and s o on), financials, contracts, projects info, drawings, partners information, etc.
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

