Ransomware victim disclosure
← All victimsCR Meyer
listed as crmeyer.com · Claimed by BrainCipher · listed 4 days ago
Status timeline
- ListedAug 31, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- Germany
- Sector
- Professional Services
- Listed on leak site
- Aug 31, 2026
About the victim
AI dossier — public-source company profileCR Meyer is a self-performing industrial general contractor founded in 1888, providing design/build, engineering, and construction services across food & beverage, pulp & paper, packaging, oil & gas, power generation, and mining sectors. The company offers a full range of services including boiler services, electrical, piping, millwrighting, and project management.
- Industry
- Industrial Contracting & Engineering
- Founded
- 1888
Attack summary
Severity: high — Confirmed exfiltration of significant business data at scale (330 GB, 275k files) including proprietary project documentation, bid/tender packages, customer data, and internal financial records from a major industrial contractor. Exposure of client lists and detailed project information poses competitive and operational risks to CR Meyer and its customers.BrainCipher claims to have exfiltrated approximately 275,000 documents totaling over 330 GB from CR Meyer, including a customer database with records from major clients (Georgia Pacific, Graphic Packaging, Packaging Corporation of America, and others), internal administrative files, and complete project documentation (drawings, specifications, bid documents, purchase orders, invoices, and correspondence).
Data the group says was taken
AI dossier — extracted from the leak post- Customer database (~250 clients)
- Client project files (Revit 3D models, drawings, specifications)
- Bid documents and tender packages
- Purchase orders and invoices
- Project schedules and correspondence
- Internal administration and accounting records
- Timesheets
- Occupational safety documentation
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteWe have about 275,000(275k) documents and files of your company, with a total size of over 330 GB. The data includes a customer database (~250 customers) — the largest ones are: Georgia Pacific (40 275 files), Graphic Packaging (35 747), Packaging Corporation of America (26 801), Irving Tissue (21 071), Essity (13 093), Molson Coors (9 975), Billerud (6 619), Kraft Foods (4 999), International Paper (4 610), Voith, Graymont, Menasha, UPS (697), Oshkosh Corp, McCain, Caterpillar, DTE Energy, Air Liquide, Burns & McDonnell, Southern Company (Plant Scherer) and hundreds of others; Internal segment (25,230 files) — administration, accounting, timesheets, occupational safety, etc.; For each project—a complete set of documents: drawings (including Revit 3D models), specifications, bid documents (tender packages with commercial proposals), purchase orders (POs), invoices, schedules, and correspondence. If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: September 12, 2026 at 13:00
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

