Ransomware victim disclosure
← All victimsIntegroy Construction
listed as INTEGROY.COM · Claimed by Cl0p · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileIntegroy Construction is a civil infrastructure contractor based in Oakville, Ontario, serving Southern Ontario. The company specialises in earthworks, sanitary and storm sewer installation, watermain installation, road construction, municipal infrastructure reconstruction, and emergency repairs. It operates in the Milton area and holds union affiliations.
- Industry
- Civil Infrastructure Construction & Excavating
- Address
- Oakville, Ontario, Canada
Attack summary
Severity: high — Cl0p is a prolific ransomware group known for large-scale data exfiltration, and the status is 'data_published', indicating confirmed data release. While the company is a mid-sized construction firm rather than critical infrastructure, published data likely includes business, employee, and potentially financial records of moderate-to-significant sensitivity.Cl0p claims to have attacked Integroy Construction and has published data (disclosed status: data_published); no specific details on encryption or exfiltration scope are provided in the leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Business contact information
- Project/contract records
- Employee records
- Financial documents
- Health & safety documentation
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteINTEGROY.COM
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

