Ransomware victim disclosure
← All victimsMaxwell Group
listed as maxwell-group.com · Claimed by BrainCipher · listed 3 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Sep 29, 2026
About the victim
AI dossier — public-source company profileMaxwell Group develops, owns, and manages luxury retirement communities and senior living care entities across seven U.S. states (Connecticut, Florida, Georgia, Indiana, New Jersey, North Carolina, and South Carolina). Founded in 1989 and headquartered in Charlotte, North Carolina, the company operates over 3,700 residential units and employs approximately 3,500 staff across development, operations, marketing, and care services.
- Industry
- Senior Living & Luxury Retirement Communities
- Address
- 3530 Toringdon Way, Suite 204, Charlotte, North Carolina 28277, USA
- Employees
- 3500
- Founded
- 1989
Attack summary
Severity: critical — Confirmed exfiltration of regulated healthcare data (resident PHI at scale, medical records, billing information) combined with sensitive financial records, banking credentials, and employee personal data. Healthcare records are federally protected (HIPAA); breach affecting 3,700+ residents constitutes critical exposure.BrainCipher claims to have exfiltrated 115 GB of data comprising 150,000 files and documents. The leaked data includes complete corporate financial records, banking credentials, tax documents, resident medical records (PHI including Medicaid/Medicare billing and therapy notes), employee personal documents, M&A strategy information, and state licenses across multiple operating jurisdictions.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial statements and forecasts
- Bank account details and reconciliations
- Corporate credit cards
- Tax returns and W-2 forms
- Resident PHI (medical records, therapy notes, incident reports)
- Medicaid/Medicare billing records
- Employee personal documents
- M&A transaction details and valuations
- Debt facility agreements
- State licenses and cost reports
Original description
AI-summarised, not from the leak postN/A I don't have reliable, verified information about a specific company operating at "maxwell-group.com." There are multiple businesses that use variations of "Maxwell Group" as a name across different industries and countries, and without access to current, verifiable data tied specifically to this domain, I cannot provide accurate details about its operations, industry, or country without risking providing false information.
The leak post
captured from the group's siteWe have over 115 GB of data — 150k files and documents containing: Complete corporate financial statements, budgets, and forecasts; Bank accounts and reconciliations (Truist); corporate CC's; Taxes and payroll (990s, W-2, tax documents, commissions); Residents PHI: Medicaid/Medicare billing, medical records, therapy notes, incident reports with nurse's notes; Employees personal documents; Strategic M&A information (transactions, valuations, due diligence); Debt facility agreements with investors; State licenses and Cost Reports across multiple states; If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: October 7, 2026 at 13:04
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

