Ransomware victim disclosure
← All victimsexpresspros.com
Claimed by Chaos · listed 6 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Sep 17, 2026
About the victim
AI dossier — public-source company profileExpress Employment Professionals is a leading U.S.-based staffing agency specializing in temporary and permanent job placement across office services, light industrial, and skilled trades sectors. Operating as a franchise with locations across multiple states and internationally, the company connects job seekers with employers and provides customized workforce solutions.
- Industry
- Staffing & Employment Services
Attack summary
Severity: medium — Data exfiltration confirmed by public disclosure phase initiation, but no proof files or screenshots advertised, no specific sensitive data types detailed (though staffing/HR context suggests potential employee/applicant PII exposure). Operational disruption not stated.The Chaos group claims to have breached Express Employment Professionals and initiated public data release after the company did not respond to direct communication attempts. The post indicates data exfiltration but provides no specific details on data types, volume, or operational impact.
What the group claims
Express Employment Professionals — Data Breach Notification & Public Disclosure We have officially initiated the public release phase regarding expresspros.com. Despite our direct attempts to establish communication, company leadership and their representatives have chosen a strategy of silence…
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

