Ransomware victim disclosure
← All victimsCirrus Aviation Services
listed as cirrusaviation · Claimed by INC Ransom · listed 5 months ago
Status timeline
- ListedJan 16, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 16, 2026
- Data size
- 100 GB
About the victim
AI dossier — public-source company profileCirrus Aviation Services is described as the largest luxury private jet charter service based in Las Vegas, Nevada. The company provides high-end private aviation services to clients, likely including high-net-worth individuals and corporate customers. No further operational details are available from the public site.
- Industry
- Luxury Private Jet Charter
- Address
- Las Vegas, Nevada, United States
Attack summary
Severity: critical — 100 GB of data has been confirmed published, including client PII, full financial databases with all transactions, NDAs, and confidential business agreements — representing large-scale exfiltration of regulated and sensitive personal and financial data belonging to high-net-worth private aviation clients.INC Ransom claims to have exfiltrated approximately 100 GB of data from Cirrus Aviation Services, including client records, financial databases, NDAs, business agreements, and other confidential corporate documents. The data has been published, indicating the victim did not meet ransom demands.
Data the group says was taken
AI dossier — extracted from the leak post- Confidential documents
- Client data
- NDAs
- Financial data
- Financial databases
- All transactions records
- Operations data
- Corporate data
- Business agreements
- Development data
What the group claims
Cirrus Aviation Services is the largest luxury private jet charter service in Las Vegas. Laek: 100GB WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

