Ransomware victim disclosure
← All victimsEastex Environmental Laboratory
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Mar 25, 2026
About the victim
AI dossier — public-source company profileEastex Environmental Laboratory, Inc. is a NELAP-accredited and TCEQ Drinking Water-approved environmental testing laboratory headquartered in Coldspring, Texas, serving clients across the state since 1986. The company operates four Texas locations — in Coldspring, Nacogdoches, Katy, and Manchaca (Austin area) — providing sample analysis and compliance support services.
- Industry
- Environmental Testing & Laboratory Services
- Address
- 35 Eastex Ln, Coldspring, TX 77331
- Founded
- 1986
Attack summary
Severity: high — Confirmed exfiltration with data published, encompassing HR and financial records (likely containing employee PII) alongside proprietary lab and compliance data; the regulated environmental testing context and published status elevate severity beyond medium.The Nightspire ransomware group claims to have exfiltrated data from Eastex Environmental Laboratory, with the disclosed status indicating data has been published. The claimed data includes experimental/lab reports, internal documents, and financial and HR records.
Data the group says was taken
AI dossier — extracted from the leak post- Experimental reports
- Internal documents
- Financial documents
- HR documents
What the group claims
- Experimental Reports- Internal Documents- Financial & HR Documents
Sources
- Victim sitewww.eastexlabs.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

