Ransomware victim disclosure
← All victimsBMS CAT
listed as Blackmon Mooring · Claimed by Hunters International · listed 1 year ago
Status timeline
- ListedApr 5, 2025
- Data leakeddate unknown
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Apr 5, 2025
About the victim
AI dossier — public-source company profileBMS CAT is a large-scale disaster recovery and restoration company founded in 1948, operating across 30+ U.S. locations. They provide fire, water, mold, and smoke damage restoration, along with specialized services including biohazard cleanup, HVAC decontamination, and critical infrastructure recovery. They service commercial, residential, and institutional clients including Fortune 500 companies.
- Industry
- Disaster Recovery & Restoration Services
- Address
- Fort Worth, Texas (headquarters); operates across 30+ U.S. locations
- Founded
- 1948
Attack summary
Severity: high — Confirmed exfiltration of data from a major national infrastructure-critical service provider (disaster recovery) that handles sensitive client information, combined with encryption of systems. The company's role in critical infrastructure recovery elevates operational risk.The hunters group claims to have both encrypted systems and exfiltrated data from BMS CAT. The leak post confirms data exfiltration occurred, though specific data categories and volume are not detailed in the post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- customer records
- business operations data
- client project information
- internal systems
What the group claims
Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

