Ransomware victim disclosure
← All victimsWinona Powder Coating
Claimed by Karakurt · listed 3 years ago
Status timeline
- Listed
Apr 24, 2023
- Data leaked
At a glance
- Group
- Karakurt
- Status
- Data leaked
- Country
- India
- Sector
- Manufacturing
- Listed on leak site
- Apr 24, 2023
About the victim
AI dossier — public-source company profileWinona Powder Coating is described as the largest provider of finishing services in the Northern Indiana/Southern Michigan region of the United States. The company specializes in E-Coat and Powder Coat finishes for industrial or manufacturing clients. Based on the leak post, it employs a workforce whose personal records were maintained in company systems.
- Industry
- Industrial Surface Finishing & Coating Services
- Address
- Northern Indiana/Southern Michigan region, USA
Attack summary
Severity: critical — Confirmed exfiltration and publication of regulated PII at scale including SSNs and DOBs for employees, combined with financial records and business contracts, meets the threshold for critical severity under data breach regulations (e.g., GLBA, state breach notification laws).Karakurt claims to have exfiltrated data including employee PII (SSN, date of birth, addresses, phone numbers), ongoing project details with client contacts and contracts, and financial/accounting documentation. The post indicates the data has been published, with no mention of encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Employee Social Security Numbers (SSN)
- Employee dates of birth
- Employee home addresses
- Employee phone numbers
- Ongoing project details
- Client contacts
- Contracts
- Financial documentation
- Accounting records
What the group claims
Winona Powder Coating is the largest provider of finishing services in the Northern Indiana/Southern Michigan region. We specialize in E-Coat and Powder Coat finishes. This is another example of a business that doesn't care about ts employees' personal information. Almost a full set of information for each worker: SSN, DOB, address, phone ... Besides that we have Winona's ongoing project details with contacts and contracts. As well as their financial and accounting documentations. Much to see. You are welcome to check that.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
