Ransomware victim disclosure
← All victimsSouthwest Air Equipment
listed as ICAFe Companies · Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 4, 2026
About the victim
AI dossier — public-source company profileSouthwest Air Equipment is a single-source equipment supplier dedicated to the spray foam industry. The company offers comprehensive services including replacement parts, repairs, and complete spray rig setups. It operates in the United States and serves clients in the spray foam contracting sector.
- Industry
- Spray Foam Equipment Supply & Services
Attack summary
Severity: high — Confirmed exfiltration of significant business data including NDAs, contracts, financials, client files, and personal information; data has been announced as pending publication, indicating material exposure of sensitive business and some PII.Akira claims to have exfiltrated corporate data from Southwest Air Equipment (operating under ICAFe Companies), including client files, NDAs, contracts and agreements, financials, confidential files, and personal information, with data publication described as forthcoming.
Data the group says was taken
AI dossier — extracted from the leak post- Client files
- NDAs
- Contracts and agreements
- Financial records
- Confidential files
- Personal information
What the group claims
Southwest Air Equipment is a single-source equipment supplier ded icated to the spray foam industry, offering comprehensive service s including replacement parts, repairs, and complete spray rig se tups. We will upload corporate data soon. Lots of clients files, NDAs, contracts and agreements, financials, confidential files, a bit o f personal information and so on.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

