Ransomware victim disclosure
← All victimsThe Execu|Search Group
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedDec 14, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Dec 14, 2021
About the victim
AI dossier — public-source company profileThe Execu|Search Group is a U.S.-based staffing and recruiting firm with over 250 employees operating across the United States. The company provides direct hire recruiting, contract staffing, staff augmentation, and workforce solutions to clients of all sizes. It maintains specialized teams in healthcare, technology, pharmaceutical, and professional services sectors.
- Industry
- Staffing & Recruiting Services
- Employees
- 250+
Attack summary
Severity: high — Data has been confirmed as published by the Snatch group. As a staffing firm, the company likely holds significant volumes of PII for job candidates (resumes, SSNs, background checks) across healthcare and pharmaceutical sectors, representing substantial sensitivity. The published status elevates this beyond medium.The Snatch ransomware group claims to have exfiltrated data from The Execu|Search Group and has published the data, as indicated by the 'data_published' disclosure status. No specific ransom amount or data volume has been stated.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Client business records
- Candidate/applicant personal data
- Healthcare sector staffing data
- Pharmaceutical sector staffing data
- Technology sector staffing data
- HR and workforce documentation
What the group claims
With 250+ employees across the U.S., we offer direct hire recruiting, contract and staff augmentation, and workforce solutions for companies of all sizes. Our healthcare, technology, pharmaceutical, and professional services teams are each led by recruiters who are truly specialized in their respective fields.
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

