Ransomware victim disclosure
← All victimsSouthern California Telephone Company
Claimed by Akira · listed 13 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Energy & Utilities
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileSouthern California Telephone Company (SCTC) is a regional telecom provider offering high-speed internet, mobility solutions, virtual fax services, and VoIP to residential and business customers across Southern California. The company has been operating for over 30 years.
- Industry
- Telecommunications
Attack summary
Severity: critical — Confirmed exfiltration of regulated/sensitive data at scale: employee PII (passports, tax documents), customer PII (phone numbers), and business confidential materials (NDAs, certificates). Telecommunications sector handles customer data subject to regulatory requirements (FCC, state telecom regulations).Akira claims to have exfiltrated approximately 34 GB of corporate data including employee personal information (passports, W-9 tax forms), customer information (phone numbers and sensitive details), contracts, agreements, NDAs, and confidential certificates.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (passports, W-9 forms)
- Customer information (phone numbers, sensitive data)
- Contracts and agreements
- NDAs
- Confidential certificates
What the group claims
Southern California Telephone Company (SCTC) is a dynamic telecom provider with over 30 years o f experience, offering a comprehensive range of services for both residential and business clie nts. Their product lineup includes high-speed internet, mobility solutions, virtual fax service s, and VoIP offerings, catering to various connectivity needs. We will upload 34gb of corporate data soon. Employee personal information (passports, w-9s and so on), customer information (phone numbers and other sensitive information), contracts and agr eements, NDAs, confidential certificates and so on.
Source
Indexed 13 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

