Ransomware victim disclosure
← All victimsBain Oil Company
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Energy
- Listed on leak site
- Mar 2, 2026
About the victim
AI dossier — public-source company profileBain Oil Company is a family-oriented HVAC and fuel delivery business based in Greensboro, North Carolina, serving the Triad region (Greensboro, High Point, Winston-Salem) since 1948. The company provides residential heating oil delivery, commercial fuel supply (gasoline, diesel, off-road fuel), and HVAC installation and maintenance services across multiple counties in North Carolina and into Virginia.
- Industry
- HVAC & Fuel Delivery Services
- Address
- 3201 Spring Garden St, Greensboro, NC 27407
- Founded
- 1948
Attack summary
Severity: medium — The disclosure status is marked as data_published suggesting exfiltration and publication occurred, but the leak post content is unavailable for verification. As a fuel delivery and HVAC company, potential exposed data could include residential customer PII, billing/payment records, and commercial fuel client details, representing moderate to significant sensitivity. Without confirmed data inventory or proof files, severity is capped at medium.The Nightspire ransomware group claims to have attacked Bain Oil Company and lists the disclosure status as data_published; however, the leak post content is currently unavailable, so specific details on encryption, exfiltration, or the nature of published data cannot be confirmed from the post alone.
What the group claims
Data is not available now.
Sources
- Victim sitewww.bainonline.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

