Ransomware victim disclosure
← All victimsHTH Companies
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Mar 4, 2026
- Data size
- 60 GB
- Records
- 9. passports
About the victim
AI dossier — public-source company profileHTH Companies Inc. is a professional industrial service provider specializing in scaffold erection, mechanical insulation, industrial cleaning, industrial maintenance, mechanical work, and painting and coatings. The company operates in the United States and serves industrial clients across multiple service disciplines. No further details on scale or headquarters are available from the leak post or a public site.
- Industry
- Industrial Services & Scaffolding
Attack summary
Severity: critical — The threat actor claims exfiltration of regulated PII at scale — including passports, driver's licenses, I-9/W-9 tax forms, and medical information for employees — alongside sensitive business data totalling 60 GB, meeting the threshold for critical severity.Akira claims to have exfiltrated over 60 GB of corporate data from HTH Companies Inc., including employee personal files, NDAs, contracts, project records, financials, and other confidential files, with publication of the data stated as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee I-9 forms
- Employee W-9 forms
- Passports
- Driver's licenses
- Medical information
- NDAs
- Contracts and agreements
- Project records
- Financial records
- Confidential corporate files
What the group claims
HTH Companies Inc. is a leading professional industrial service p rovider, specializing in scaffold erection, mechanical insulation , industrial cleaning, industrial maintenance, mechanical work, a nd painting and coatings. We will upload over 60gb of corporate data soon. Employee persona l files (i9, w9, passports, DLs, medical information), NDAs, cont racts and agreements, projects, financials, confidential files, a nd so on.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

