Ransomware victim disclosure
← All victimsO'Brien Engineering & Architecture
listed as obrieneng.com · Claimed by INC Ransom · listed 18 hours ago
Status timeline
- Listed
Jun 6, 2026
- Data leaked
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- US
- Listed on leak site
- Jun 6, 2026
- Data size
- 20 GB
- Records
- 20 files
About the victim
AI dossier — public-source company profileO'Brien Engineering & Architecture (OEI) is a mission-driven engineering and architecture firm founded in 1987, specializing in designing resilient facilities for federal, state, and local sectors. The firm serves military installations, medical/healthcare facilities, water infrastructure, and critical facility assets across the U.S. and its territories, with expertise in horizontal and vertical facility design, dam and levee safety, and construction phase services.
- Industry
- Engineering & Architecture Services
- Founded
- 1987
Attack summary
Severity: critical — Confirmed exfiltration of classified/sensitive government contracting data (DOD, military installations, VA projects, SAM.gov references) with proof files published. Defense and federal procurement data exposure poses national security risk.INC Ransom claims to have exfiltrated data from O'Brien Engineering & Architecture, alleging access to contract NDAs, confidential documents, and materials related to government (DOD/military/VA/SAM.gov) work. The group published 23 proof files.
Data the group says was taken
AI dossier — extracted from the leak post- Contract NDAs
- Confidential documents
- Government/military project files
- VA-related materials
- SAM.gov related records
The group's post references roughly 23 proof files.
What the group claims
contract nda confidential gov/military/va/sam.gov other
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":722,"announcements":[{"_id":"6a232c515ae71db30c46b0a3","company":{"company_name":"obrieneng.com","country":"US","revenue":20000000},"categories":["Proof"],"description":["contract%20nda%20confidential%20%20%20gov%5Cdot%5Cmilitary%5Cva%5Csam.gov%20other"],"logo":"6a232c515ae71db30c46b089","proof":["6a232c515ae71db30c46b072","6a232c515ae71db30c46b073","6a232c515ae71db30c46b074","6a232c515ae71db30c46b075","6a232c515ae71db30c46b076","6a232c515ae71db30c46b077","6a232c515ae71db30c46b078","6a232c515ae71db30c46b079","6a232c515ae71db30c46b07a","6a232c515ae71db30c46b07b","6a232c515ae71db30c46b07c","6a232c515ae71db30c46b07d","6a232c515ae71db30c46b07e","6a232c515ae71db30c46b07f","6a232c515ae71db30c46b080","6a232c515ae71db30c46b081","6a232c515ae71db30c46b082","6a232c515ae71db30c46b083","6a232c515ae71db30c46b084","6a232c515ae71db30c46b085","6a232c515ae71db30c46b086","6a232c515ae71db30c46b087","6a232c515ae71db30c46b088"],"visits":262,"leakAt":-58637220540000,"createdAt":1780690001957,"updatedAt":1780690001957,"__v":0},{"_id":"6a21bd57d152110a6a4b4f68","company":{"company_name":"Stuga%20Machinery","country":"GB","revenue"…Data the group says was taken
- contracts
- NDAs
- confidential documents
- government/military records
Screenshot of the leak post

Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
