Ransomware victim disclosure
← All victimsXpera Emergency Security Management (ESM)
listed as xpera.ca · Claimed by BrainCipher · listed 3 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- Canada
- Sector
- Technology
- Listed on leak site
- Sep 17, 2026
About the victim
AI dossier — public-source company profileXpera is Canada's leading risk mitigation and security services provider, operating for over 50 years with 20+ locations and approximately 1,800 experts. The company specializes in private investigations, threat risk assessment, executive protection, labour dispute management, emergency staffing, and security solutions across multiple sectors.
- Industry
- Private Investigation & Security Services
- Employees
- 1800
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated personal data (SINs, financial accounts, health savings data) affecting 1,800+ employees, plus sensitive business intelligence (M&A strategy, financial statements) and customer data. SINs and financial information constitute highly regulated PII in Canada.BrainCipher claims to have exfiltrated 20 GB of data from Xpera, including highly sensitive employee personal information (SINs, bank details, addresses, dates of birth, RRSP/TFSA records), salary and budget information, M&A strategy documents, 16 years of financial statements, and customer data. The group set a deadline of September 25, 2026 at 13:00 for presumed ransom negotiation.
Data the group says was taken
AI dossier — extracted from the leak post- Employee Social Insurance Numbers (SINs)
- Bank account details
- Employee salaries
- Employee addresses and dates of birth
- RRSP/TFSA information
- Budget documents
- M&A strategy
- 16 years of financial statements
- Customer data
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteWe have 20 GB of data belonging to this company. The data contains information such as employees' SINs, bank account details, salaries, addresses, dates of birth, RRSP/TFSA information, budgets, M&A strategy, 16 years of financial statements, and customer data. If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: September 25, 2026 at 13:00
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

