Ransomware victim disclosure
← All victimsA.T. Chadwick
listed as atchadwick.net · Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 12, 2026
- Ransom demanded
- $159.1M
- Estimated revenue
- $159.1M
About the victim
AI dossier — public-source company profileA.T. Chadwick is a mechanical contracting firm headquartered in Bensalem, Pennsylvania, founded in 1966. The company provides plumbing, heating, air-conditioning, refrigeration, process piping, and field management services. It employs approximately 500 people and reports annual revenue of approximately $159.1 million.
- Industry
- Mechanical Contracting (Plumbing, HVAC & Refrigeration)
- Address
- Bensalem, Pennsylvania, United States
- Employees
- 500
- Founded
- 1966
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by the ransomware group, confirming exfiltration of significant business data from a mid-sized construction management firm with ~500 employees and $159M revenue. No confirmed regulated PII at scale (e.g., medical or government data) to elevate to critical.The Incransom group claims to have published data belonging to A.T. Chadwick, indicating exfiltration of company data with the status listed as data_published. No specific data volume was stated, but the disclosure is marked as fully published.
Data the group says was taken
AI dossier — extracted from the leak post- Company financial records
- Employee data
- Operational/project records
What the group claims
A.T. Chadwick is a mechanical contracting firm that offers services in plumbing, heating, air-conditioning, refrigeration, process piping, and field management. The company was founded in 1966 and is headquartered in Bensalem, Pennsylvania. Employees: 500 Revenue: $159.1 Million Industry: Construction Management Phone Number: (215) 245-5800
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

