Ransomware victim disclosure
← All victimsBusiness Automation Specialists of Minnesota
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 4, 2026
- Data size
- 10 GB
About the victim
AI dossier — public-source company profileBusiness Automation Specialists of Minnesota (BASM) is a Microsoft Partner specializing in the implementation, consultation, customization, and support of Microsoft Dynamics 365 Business Central and NAV ERP systems. The company operates in the United States and serves clients requiring enterprise resource planning solutions. Its focus is on business process automation through Microsoft's Dynamics platform.
- Industry
- Microsoft Dynamics ERP Implementation & Consulting
Attack summary
Severity: critical — Confirmed exfiltration of regulated and sensitive data at multiple levels: employee PII (passports, DLs), medical records (HIPAA-relevant), client files, and financial records — all categories that constitute regulated or highly sensitive data under US privacy frameworks.Akira claims to have exfiltrated approximately 10 GB of corporate data from BASM, including employee personal identification documents, medical files, NDAs, contracts, financials, project files, and client files, with publication of the data stated as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Employee medical files
- NDAs
- Contracts and agreements
- Financial records
- Project files
- Client files
- Internal confidential documents
What the group claims
Business Automation Specialists (BASM) is a Microsoft Partner tha t focuses on providing implementation, consultation, customizatio n, and support for Microsoft Dynamics 365 Business Central and NA V. We will upload 10 gb of corporate data soon. Employee personal fi les (passports, DLs, medical files), NDAs, contracts and agreemen ts, financials, projects, clients' files, internal confidential f iles, and so on.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

