Ransomware victim disclosure
← All victimsThe Miller Group
Claimed by Dark Project · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Dark Project
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileThe Miller Group (Multiplex Division) is a retail display manufacturer operating facilities in Dupo, Illinois and Richmond, Virginia. They design and produce custom display solutions for retail environments.
- Industry
- Custom Retail Displays & Fixtures Manufacturing
- Address
- Dupo, Illinois and Richmond, Virginia, USA
Attack summary
Severity: high — Confirmed exfiltration of 500 GB including regulated PII at scale (Social Security numbers, home addresses for employees) plus sensitive business data (financial documents, technical drawings). Data is already published.Dark Project claims to have exfiltrated 500 GB of confidential data including employee PII, financial documents, and complete project drawings. The group has published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Employees' Social Security numbers
- Employee email addresses
- Employee home addresses and ZIP codes
- Financial documents (budgets, transactions, internal reports)
- Complete project drawings and technical diagrams
What the group claims
About The Miller Group The Miller Group refers to The Miller Group - Multiplex Division, a retail display manufacturer with operations spanning Dupo, Illinois and Richmond, Virginia As a result of the cyberattack, the company lost control of 500 GB of confidential data, including: employees’ Social Security numbers, email addresses, home addresses, and ZIP codes—plain Excel spreadsheets; financial documents in PDF format—budgets, transactions, and internal reports; complete project drawings—working diagrams and perspective sketches.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

