Ransomware victim disclosure
← All victimsSavvy Hawk
Claimed by Akira · listed 2 months ago
Status timeline
- Listed
Mar 20, 2026
- Data leaked
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Not Found
- Listed on leak site
- Mar 20, 2026
- Data size
- 941 GB
About the victim
AI dossier — public-source company profileSavvy Hawk is a Miami-based IT service provider specializing in business-focused communication solutions for small to enterprise-level clients. Their services include custom cloud solutions, data backup and recovery, and VoIP telephone services, all aimed at enhancing productivity and business continuity.
- Industry
- IT Services & Business Communications
- Address
- Miami, Florida, United States
Attack summary
Severity: critical — The claimed dataset includes regulated PII at scale (SSNs, passports, medical records), financial data, and client payment card information across what appears to be a multi-client IT provider, amplifying downstream exposure risk to the company's clients.Akira claims to have exfiltrated 941 GB of corporate data from Savvy Hawk, including detailed employee personal information (passports, driver's licenses, SSNs, medical records), HR files, client credit card data, financials, and contracts, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security Numbers (SSNs)
- Employee medical records
- HR files
- Client credit card information
- Financial records
- Contracts and agreements
What the group claims
Savvy Hawk is a Miami-based IT service provider that specializes in business-focused communication solutions for small to enterpri se-level clients. They offer services such as custom cloud soluti ons, data backup and recovery, and VoIP telephone services, all d esigned to enhance productivity and business continuity. We will upload 941gb of corporate data soon. Detailed employee pe rsonal information (passports, DLs, SSNs, medical records and so on), HR files, client's credit cards and other information, finan cials, contracts and agreements, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
