Ransomware victim disclosure
← All victimsEllsworth Cooperative Creamery
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedApr 7, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Apr 7, 2024
About the victim
AI dossier — public-source company profileEllsworth Cooperative Creamery is a Wisconsin-based cheese manufacturer and cooperative sourcing milk from 180+ family dairy farms. They produce over 80 cheese varieties and 180,000 lbs of fresh cheese curds daily, with retail locations in Ellsworth and Menomonie, Wisconsin, and online sales channels. The company markets itself as the 'Cheese Curd Capital of Wisconsin' with a century-plus operating history.
- Industry
- Dairy Products Manufacturing & Cheese Production
- Address
- Ellsworth, Wisconsin, United States (primary location); Menomonie, Wisconsin, United States (secondary location)
Attack summary
Severity: medium — Disclosed status indicates data_published, confirming exfiltration and public release. However, no leak post content, proof files, or specific data inventory details were captured to assess the scope or sensitivity of exposed information. Agricultural/food production sector typically involves moderate-sensitivity operational and customer data.Blacksuit claims to have attacked Ellsworth Cooperative Creamery and published data. No leak post excerpt was provided to verify specific claims regarding encryption, exfiltration, or the nature of exposed data.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Business operations data
- Internal systems
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

