Ransomware victim disclosure
← All victimsItasca Consulting Group
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jan 13, 2026
- Data size
- 20 GB
About the victim
AI dossier — public-source company profileItasca Consulting Group is a global engineering consulting and software firm specializing in geomechanics, hydrogeology, and microseismics. The company serves clients in mining, civil, and energy sectors with numerical modeling software and expert consulting services. It operates internationally with offices across multiple continents.
- Industry
- Geomechanical & Hydrogeological Engineering Consulting & Software
- Employees
- 51-200
Attack summary
Severity: critical — The group claims exfiltration of regulated PII at scale (personal documents, addresses, financial data, credit card information) alongside sensitive business data (NDAs, client files, financials), with 20 GB of data imminently to be published.Akira claims to have exfiltrated approximately 20 GB of corporate data from Itasca Consulting Group, encompassing employee personal information, project and client data, internal confidential files, financial records, credit card information, and NDAs; publication of the data is stated as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (addresses, phone numbers, emails)
- Scans of personal documents
- Project files
- Client information
- Internal confidential files
- Financial records
- Credit card information
- NDAs
What the group claims
Itasca is a global engineering consulting and software firm, work ing primarily with the geomechanics, hydrogeological and microsei smics communities. We will upload 20gb of corporate data soon. Detailed employee per sonal information (addresses, phones, emails, scans of personal d ocuments and so on), projects, client information, internal confi dential files, financials, credit cards, NDAs and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

