Ransomware victim disclosure
← All victimsJack Rutherford Customs Brokers Ltd / The Rutherford Group
Claimed by Blacknevas · listed 4 hours ago
Status timeline
- ListedOct 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Blacknevas
- Status
- Data leaked
- Country
- Canada
- Listed on leak site
- Oct 6, 2026
- Data size
- 1.2 TB
- Records
- 145146 files
About the victim
AI dossier — public-source company profileJack Rutherford Customs Brokers Ltd, operating as The Rutherford Group, is a family-owned Canadian logistics provider founded in 1974. It offers customs brokerage (import/export clearance, CARM, surety bonds with PIP status), transportation services within Canada, the US, and internationally, and warehousing including bonded facilities and FDA-certified warehouses in Port Huron, Michigan.
- Industry
- Customs Brokerage & Cross-Border Logistics
- Address
- Stratford, Ontario, Canada
- Founded
- 1974
Attack summary
Severity: high — Confirmed exfiltration of 1.2 TB of data from a logistics company handling cross-border trade, customs compliance, and warehousing. Exposure includes operational logistics records, client shipment data, and regulatory compliance documentation. Supply-chain criticality and data volume warrant high severity.BlackNevas claims to have exfiltrated 1.2 TB of data from the company. The group alleges the victim was compromised via Computer Country & Networks, a shared IT service provider. No specific ransom demand is stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Customs brokerage records (import/export clearance files, CARM data, surety bond documentation)
- Client logistics information (shipment tracking, carrier documentation)
- Transportation and warehousing operational data
- Potentially PII of business contacts and clients
What the group claims
A Canadian customs brokerage company operating under the brand The Rutherford Group. Founded in 1974 by Jack Rutherford in Stratford, Ontario. Provides customs brokerage, transportation, and warehousing services including bonded warehouses. Family-owned business (second generation). Serviced by Computer Country & Networks (www.computercountry.ca).
The leak post
captured from the group's site[ Optimum First Mortgage (Pear's acting group's promotional blog) ](http://ctyfftrjgtwdjzlgqh4avbd35sqrs6tde4oyam2ufbjch6oqpqtkdtid.onion/d7ba2a3f-0d92-4bc9-b30d-6f0edbeaf54b) [ Mefa Group www.mefagroup.com.tr / MEFA Endüstri www.mefaendustri.com / and (Efachem, EcoPolymer, Milkrun Lojistik) https://send.exploit.in/#37608d72633301fc62801dfdf9111dbe!BsYvGiQz6WmjZo1VvPwTi8lU2K7prrPY2q6CdMORZn0List of files. For details and cooperation, write to Telegram https://t.me/BlackNevas or email [email protected] Group is a Turkish industrial group (headquartered in Ankara), founded in 2006. It operates in industrial manufacturing, plastics, rubber, processing, and logistics. The group has over 115,000 m² of production space, over 2,000 employees, and several facilities in Turkey, Romania, and Poland. Its main areas of focus are the automotive industry, white goods, and related industries.MILKRUN — Milkrun Lojistik, the group's logistics division. It provides integrated and smart logistics solutions for group companies and partners (focusing on efficiency, digitalization, and sustainability). It is not the Australian grocery delivery service of a similar name.Efachem, a division specia…
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

