Ransomware victim disclosure
← All victimsDoAllTech
Claimed by Spacebears · listed 8 days ago
Status timeline
- ListedJul 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Spacebears
- Status
- Data leaked
- Country
- South Korea
- Sector
- Technology
- Listed on leak site
- Jul 21, 2026
About the victim
AI dossier — public-source company profileDoAllTech is a South Korean construction IT company specializing in technology platforms and services including Web Services, H/W Services, and BIM (Building Information Modeling) solutions. They focus on research and development to support digital transformation in the construction sector.
- Industry
- Construction IT & Digital Services
Attack summary
Severity: high — Confirmed exfiltration of PII (employee and client personal data) and financial documents represents significant exposure of regulated personal data at an organizational scale, with financial information adding material sensitivity.The spacebears group claims to have exfiltrated personal information of employees and clients, along with financial documents and other files from DoAllTech. No operational encryption is explicitly mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal information
- client personal information
- financial documents
What the group claims
The Company is leading the construction IT industry with the best technology and various experiences, and striving to grow with a various customers in pursuit of technology platform change and innovation through persistent research and development in introduction of Web Services, H/W Services, BIM Services, and new technologies.-Personal information of employees and clients -Financial documents -Other files https://***.com/en/
Sources
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

