Ransomware victim disclosure
← All victimsGPF Lewis
Claimed by Hunters International · listed 1 year ago
Status timeline
- ListedMay 5, 2025
- Data leakeddate unknown
At a glance
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Construction
- Listed on leak site
- May 5, 2025
About the victim
AI dossier — public-source company profileGPF Lewis is an established UK-based construction and refurbishment specialist operating across multiple sectors including commercial, residential, education, healthcare, leisure, industrial, and hospitality. They deliver projects ranging from interior fit-outs and new builds to structural alterations, with recent work on heritage venues and life science facilities.
- Industry
- Construction & Refurbishment
Attack summary
Severity: medium — Confirmed dual attack (encryption + exfiltration) against a significant UK construction firm with likely access to client project data, financial records, and employee information. However, no proof files are advertised and no specific regulated data categories are named.The hunters group claims to have both encrypted systems and exfiltrated data from GPF Lewis. No specific details on data type or operational impact are provided in the truncated leak post.
What the group claims
Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

