Ransomware victim disclosure
← All victimsCedar Grove Warehouse
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 18, 2026
- Data size
- 27 GB
About the victim
AI dossier — public-source company profileCedar Grove Warehouse is a family-owned logistics and warehousing company based in the United States. It offers dock-to-dock logistics solutions, rail car cross docking, and multiple storage options including refrigerated, freezer, and dry storage facilities.
- Industry
- Logistics & Warehousing
- Employees
- 100+
Attack summary
Severity: critical — Confirmed exfiltration of PII at scale (SSNs, passports, government-issued IDs for 100+ individuals) alongside sensitive financial, HR, and client data constitutes regulated/sensitive data exposure meeting the critical threshold.Akira claims to have exfiltrated approximately 27 GB of corporate data, including personal employee records (SSNs, passports, national IDs, driver's licenses for more than 100 individuals), financial records, HR files, project files, client files, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee SSNs
- Passports
- National IDs
- Driver's licenses
- Financial records
- HR files
- Project files
- Client files
- NDAs
What the group claims
Cedar Grove Warehouse is a family-owned logistics and warehousing company that offers a range of services including dock-to-dock l ogistics solutions, rail car cross docking, and various storage o ptions such as refrigerated, freezer, and dry storage. We will upload almost 27gb of corporate data soon. Personal files of employees (SSNs, passports, national IDs and DLs of more than 100 ppl and other personal information), financials, HR files, p rojects, client files, NDAs and so on.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

