Ransomware victim disclosure
← All victimsSangre de Cristo Electric Association
Claimed by Incransom · listed 4 hours ago
Status timeline
- ListedOct 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Energy & Utilities
- Listed on leak site
- Oct 2, 2026
About the victim
AI dossier — public-source company profileSangre de Cristo Electric Association (SDCEA) is a utility cooperative providing electrical distribution services in the US, operating substations, transformers, and feeders across its service territory.
- Industry
- Energy & Utilities
Attack summary
Severity: critical — Confirmed exfiltration of customer PII and financial data at scale, combined with operational technology infrastructure details, control credentials, and SCADA/EMS system information affecting critical energy infrastructure. Threat to disrupt services adds operational risk.Incransom claims to have exfiltrated customer personally identifiable information, financial and payment data, utility account information, operational technology environment details including electrical distribution infrastructure, SCADA/EMS systems, control-system credentials, API keys, and OT security configurations. The group alleges negotiations failed after the CEO declined further discussion and has threatened further disruptive actions.
Data the group says was taken
AI dossier — extracted from the leak post- Customer PII
- Financial and payment data
- Utility account information
- Electrical distribution infrastructure details
- Substation and transformer configurations
- Feeder information
- SCADA/EMS system data
- Outage information
- Control-system credentials
- API keys
- OT security configurations
What the group claims
Sangre de Cristo Electric Association (SDCEA) has been informed that a substantial volume of sensitive information has been compromised. The affected information includes customer personally identifiable information, financial and payment data, utility account information, and information associated with the organization’s energy infrastructure and operational technology environment. The information includes details concerning electrical distribution infrastructure, substations, transformers, feeders, operational systems, renewable-generation assets, outage information, and SCADA/EMS-related environments. The compromise data also include highly sensitive authentication and security information, including control-system credentials, API keys, and OT security configurations. We previously proposed resolving the incident through a peaceful and confidential process. According to our account, negotiations were subsequently discontinued after SDCEA CEO Jon Beyer indicated that the organization had decided to end discussions. As a result, we are issuing this public statement concerning the incident. In addition, we will take further disruptive actions to ensure that, in the future, those responsible for making these decisions approach the security of the resources entrusted to them—including the people within their area of responsibility—with greater awareness and seriousness.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

