Ransomware victim disclosure
← All victimsEhlers, Inc.
listed as ehlers-inc.com · Claimed by lockbit3 · listed 1 year ago
Status timeline
- Listed
May 6, 2025
- Data leaked
At a glance
- Group
- lockbit3
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- May 6, 2025
About the victim
AI dossier — public-source company profileEhlers, Inc. is an industry-leading municipal advisory firm specializing in public finance solutions for local governments, school districts, and public agencies across Minnesota, Wisconsin, Colorado, Illinois, and Kansas. The firm provides integrated services including debt issuance, school finance, economic development, and investment management.
- Industry
- Municipal Advisory & Public Finance
Attack summary
Severity: high — Confirmed data exfiltration from a municipal finance advisory firm handling sensitive government and school district financial data, bond issuances, and client information at scale across five US states. Exposure of such records could compromise multiple public sector entities and their constituents.The LockBit3 group claims to have exfiltrated data from Ehlers, Inc. and has published the data. Specific details on data categories and operational impact are not provided in the leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Municipal bond issuance records
- Client financial information
- School district budgeting data
- Government agency details
- Debt management documentation
- Investment strategy documents
What the group claims
Ehlers is an industry-leading municipal advisory firm serving Minnesota, Wisconsin, Colorado, Illinois and Kansas. We leverage centuries of combined experience and specialized expertise to deliver innovative, fully integrated public finance solutions...
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
