Ransomware victim disclosure
← All victimsEasypak
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jan 29, 2026
- Data size
- 70 GB
- Records
- 30 employees
About the victim
AI dossier — public-source company profileEasypak is a provider of thermoformed packaging solutions serving food, consumer goods, medical, and industrial markets globally. The company specializes in dependable, high-performing plastic packaging across a wide range of applications and industries.
- Industry
- Thermoformed Plastic Packaging Manufacturing
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale, including SSNs for both employees and customers, alongside financial and contractual data; 70 GB total with data_published status indicates active disclosure of sensitive regulated data.Akira claims to have exfiltrated approximately 70 GB of corporate data from Easypak, including employee SSNs (at least 30 individuals), customer SSNs, contracts, financial records, NDAs, and other confidential files, with publication of the data imminent or underway.
Data the group says was taken
AI dossier — extracted from the leak post- Employee SSNs (at least 30)
- Customer SSNs
- Contracts and agreements
- Financial records
- NDAs
- Confidential corporate files
- Employee personal information
What the group claims
EasyPak is a leading provider of thermoformed packaging solutions for a wide range of industries and applications globally. We off er dependable, high-performing plastic packaging for food, consum er goods, medical, and industrial applications. We will upload 70gb of corporate data soon. Very detailed employe es (SSNs of 30 employees and other personal information), custom ers' SSNs, lot of contracts and agreements, financials, confident ial files, NDAs and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

