Ransomware victim disclosure
← All victimsThompson Creek Window Company
listed as thompsoncreek.com_wa · Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedJul 15, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Jul 15, 2024
About the victim
AI dossier — public-source company profileThompson Creek Window Company is a Mid-Atlantic region home improvement company specializing in manufacturing and customizing replacement windows, doors, gutters, siding, and roofing products. Operating since 1980, the company serves the residential improvement market across the Mid-Atlantic region.
- Industry
- Home Improvement & Replacement Windows
- Address
- 4200 Parliament Place Suite 600, Lanham, MD 20706, USA
- Founded
- 1980
Attack summary
Severity: high — Confirmed exfiltration of 750 GB of sensitive business and personal data including financial records, payroll, tax forms, and employee/client PII at significant scale.BlackBasta claims to have exfiltrated approximately 750 GB of corporate data including financial records, human resources files, payroll information with personal tax forms, and employee and client personal documents.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data
- Financial and accounting records
- Human Resources and hiring data
- Payroll records
- Personal tax forms
- Employment agreements
- Employee personal documents
- Client personal documents
What the group claims
Thompson Creek® Window Company is the Mid-Atlantic region’s premier home improvement replacement products company. We have been customizing and manufacturing replacement windows, doors, gutters, siding and roofing in the Mid-Atlantic region since 1980.SITE: www.thompsoncreek.com Address : 4200 Parliament Place Suite 600 Lanham, MD 20706 USAALL DATA SIZE: ≈750gb 1. Corporate data 2. Financial data, Accounting… 3. Human Resources, Hire data… 4. Payroll, personal Tax forms, Agreements… 5. Personal docs employees, clients… & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

