Ransomware victim disclosure
← All victimsZelham, Inc.
listed as Zelham · Claimed by Thegentlemen · listed 3 hours ago
Status timeline
- ListedOct 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Listed on leak site
- Oct 3, 2026
About the victim
AI dossier — public-source company profileZelham, Inc. is a U.S.-based hospitality renovation general contractor headquartered in Boise, Idaho, specializing in hotel remodeling, rebranding, and ADA conversions. The company operates across 15 states with licenses in 47 states and works with 20+ major hotel brands including Marriott, Hilton, IHG, Sonesta, and Four Seasons.
- Industry
- Hospitality Renovation & General Contracting
- Address
- Boise, Idaho, USA
- Employees
- 55-57
- Founded
- 2000
Attack summary
Severity: low — The leak post contains only a company announcement with no proof files, screenshots, or specific data inventory listed. No operational impact or confirmed data exposure details are stated.The threat actor claims to have compromised Zelham, Inc. and published data. No specific details are provided in the leak post regarding what data was exfiltrated or the nature of the attack (encryption vs. exfiltration-only).
What the group claims
zelham.com rocketreach.co/zelham-inc-profile_b580fe5ef66e1a3f Zelham, Inc. is a U.S. hospitality renovation general contractor headquartered in Boise, Idaho, founded in 2000 and owned since 2023 by President & CEO Stephen Horel. The company specializes in hotel remodeling, rebranding, and ADA conversions, with 500+ completed projects and licenses in 47 states. It employs approximately 55–57 people across 15 states, generating an estimated annual revenue of $9.6M–$41.6M (sources vary). Zelham works with 20+ major hotel brands (Marriott, Hilton, IHG, Sonesta, Four Seasons), offering pre-construction planning, free estimates, and turnkey project management.
Sources
- Victim sitezelham.com
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

