Ransomware victim disclosure
← All victimsThomson Broadbent
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedJan 25, 2022
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Engineering
- Listed on leak site
- Jan 25, 2022
About the victim
AI dossier — public-source company profileThomson Broadbent is a specialist consultancy that provides advice to homeowners, developers, private estates, and landowners whose properties are affected by new or existing road, rail, airport, and electricity power line projects. The firm guides clients through statutory compensation and compulsory purchase processes arising from infrastructure development. It operates in the United Kingdom-focused property and infrastructure advisory sector.
- Industry
- Property & Infrastructure Compensation Consultancy
Attack summary
Severity: high — Data has been published by the threat actor, confirming exfiltration. The firm handles sensitive client property, legal, and financial compensation data relating to landowners and developers, representing significant business and potentially personal data exposure.The Snatch ransomware group claims to have attacked Thomson Broadbent and has published data (disclosed status: data_published), indicating exfiltration of company data, though the specific volume and nature of files have not been detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Client property records
- Landowner and developer correspondence
- Statutory process documentation
- Internal business files
What the group claims
Thomson Broadbent provides high quality advice to homeowners, developers, private estates and landowners whose properties are impacted by new road, rail, airport and existing or new electricity power line projects. Our role is to guide the landowner through the statutory processes and with our specialist
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

