Ransomware victim disclosure
← All victimsDaricon
listed as https://daricon.com/ (military US/CA/NATO) · Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 26, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Feb 26, 2026
- Data size
- 400 GB
About the victim
AI dossier — public-source company profileDaricon (daricon.com) is a US-based defense contractor operating within the US, Canadian, and NATO military supply chain. The company handles contracts with the US and Canadian armies and is involved in international logistics and shipments. It also appears to have involvement in energy-sector projects in regions including Iraq and Uganda.
- Industry
- Defense & Military Contracting
Attack summary
Severity: critical — The exfiltration involves 400 GB of highly sensitive data including PII and passport data of senior NATO military officers, military contracts, classified correspondence with NATO and US Army personnel, and operational documentation — constituting a serious national security and regulatory data breach at scale.INC Ransom claims to have exfiltrated approximately 400 GB of data from Daricon, including classified and sensitive military correspondence, contracts, personal data of NATO and US Army personnel, and confidential documentation related to international operations.
Data the group says was taken
AI dossier — extracted from the leak post- NATO and US Army employee correspondence
- Confidential documents
- NATO general signatures
- Passport and address data of NATO generals
- Shipment records to various countries
- Photos and videos
- Technical drawings
- Employee personal data (names, emails, phone numbers)
- US and Canadian Army contracts
- Documentation on oil operations in Iraq and Uganda
What the group claims
400 GB of data, correspondence with NATO and US Army employees, confidential documents, signatures of NATO generals, their passport addresses, shipments to various countries, photos and videos, drawings, personal data, emails of employees of various US and NATO armies, numerous files, phone numbers, personal data, contracts with the Canadian and US Army, documentation on other companies involved in oil in Iraq, Uganda, and elsewhere.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

