Ransomware victim disclosure
← All victimsJohnson Boiler Works
Claimed by Losttrust · listed 3 years ago
Status timeline
- ListedSep 26, 2023
- Data leakeddate unknown
At a glance
- Group
- Losttrust
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Sep 26, 2023
About the victim
AI dossier — public-source company profileJohnson Boiler Works is a residential and commercial HVAC, plumbing, and boiler service company based in Benwood, West Virginia. The company provides air conditioning installation and maintenance, heating and furnace repair, boiler replacement, sheet metal work, and licensed plumbing services. It serves customers across the tri-state area encompassing West Virginia, Ohio, and Pennsylvania.
- Industry
- HVAC, Plumbing & Boiler Services
- Address
- 53 Marshall St. North, Benwood, WV 26031
Attack summary
Severity: medium — Data is listed as published, indicating some level of confirmed exfiltration, but the target is a small local HVAC/plumbing contractor with no indication of regulated data (e.g., medical, financial, government) at scale and no data volume or specific sensitive categories disclosed.The Losttrust ransomware group claims to have compromised Johnson Boiler Works and lists the incident as data_published, indicating exfiltration and/or publication of company data. The leak post text is minimal and no specific data categories or volume are described.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Customer information
- Operational data
What the group claims
Johnson Boiler is one of the best, instant and efficient service provider in town. We are utilizing their services since so many years and we are quite satisfied with their level of professionalism in the area of heating and cooling services.
Sources
- Victim sitejohnsonboiler.com
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

