Ransomware victim disclosure
← All victimsFulcrum Construction
Claimed by Akira · listed 4 months ago
Status timeline
- ListedJan 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Jan 30, 2026
- Data size
- 12 GB
About the victim
AI dossier — public-source company profileFulcrum Construction is a national general contractor based in the United States that partners with retailers, developers, and property owners on construction projects. The company focuses on connecting communities through commercial and retail construction. No additional details are available from a public website.
- Industry
- General Contracting & Retail Construction
Attack summary
Severity: critical — The claimed exfiltration includes regulated PII at scale (passports, driver's licenses, credit card data, HR records) alongside sensitive financial and contractual business data, meeting the threshold for critical severity.Akira claims to have exfiltrated approximately 12 GB of corporate data from Fulcrum Construction, including HR files, passports, driver's licenses, financial records, credit card data, confidentiality agreements, contracts, and project files, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- HR files
- Passports
- Driver's licenses
- Employee documents
- Internal confidential files
- Financial records
- Credit card data
- Confidentiality agreements
- Contracts and agreements
- Project files
What the group claims
Fulcrum Construction is a leading national general contractor tha t partners with retailers, developers and property owners to conn ect people with their communities. We will upload 12gb of corporate data soon. Lots of HR files, pas sports, DLs and other employee documents, internal confidential f iles, financials, credit cards, confidentiality agreements, contr acts and agreements, projects and so on.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

