Ransomware victim disclosure
← All victimsR. L. Larson Excavating Inc.
listed as R L Larson Excavating · Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileR. L. Larson Excavating Inc. is an excavating contractor based in St. Cloud, Minnesota. The company operates in the construction sector, providing excavation and related site preparation services. No additional details about scale or founding are publicly available from the provided sources.
- Industry
- Excavation & Site Preparation Contracting
- Address
- St. Cloud, MN, United States
Attack summary
Severity: high — The group claims exfiltration of regulated personal data (driver's licenses, W-9/tax forms containing SSNs) alongside significant business data totalling ~30 GB, with publication imminent; this constitutes confirmed exfiltration of PII and financial records at meaningful scale.The Akira ransomware group claims to have exfiltrated approximately 30 GB of corporate data from R. L. Larson Excavating Inc., with planned publication of employee personal information (driver's licenses, W-9 forms), financial records, drawings and specifications, contracts and agreements, and project documentation.
Data the group says was taken
AI dossier — extracted from the leak post- Employee driver's licenses
- W-9 tax forms
- Financial records
- Drawings and specifications
- Contracts and agreements
- Project documentation
What the group claims
R. L. Larson Excavating Inc., is an excavating contractor based i n St. Cloud, MN. We will upload 30gb of corporate data soon. Personal data of empl oyees (DLs, w9 forms and others), financials, drawings and specif ications, contracts and agreements, projects, and so on.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

