Ransomware victim disclosure
← All victimsIlya Construtora
Claimed by Ransomhouse · listed 2 hours ago
Status timeline
- ListedSep 5, 2026
Current state: Listed for ransom
At a glance
- Group
- Ransomhouse
- Status
- Listed for ransom
- Country
- Brazil
- Sector
- Construction
- Listed on leak site
- Sep 5, 2026
About the victim
AI dossier — public-source company profileIlya Construtora is a construction company based in Brazil. Limited public information is available about the firm's specific operations, scale, or service offerings.
- Industry
- Construction
Attack summary
Severity: low — The company is listed with claimed evidence status, but no proof files, data inventory, ransom demand, or operational impact details are provided in the leak post. The listing alone without substantiating proof or data disclosure description warrants a low severity rating pending confirmation of actual data exfiltration.Ransomhouse lists Ilya Construtora with 'EVIDENCE' status on their leak site, indicating claimed data exfiltration. No specific details on data types, encryption, or proof files are disclosed in the available leak post excerpt.
The leak post
captured from the group's siteBelow is a list of companies that either have considered their financial gain to be above the interests of their partners / individuals who have entrusted their data to them or have chosen to conceal the fact that they have been compromised. [Jiangsu Zenergy Battery Technologies Group Co., Ltd. ](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/r/dc227a632118c7c3f9c1e30d3715c607390ee1ae) [Ma Pak Leung Company Limited ](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/r/08394e9fad8016695748ec838b6874bc2d0a8824) [ REXT Holdings Co., Ltd. Status:EVIDENCE, TECHVENTURES BANK S.A. Status:EVIDENCE, City of Beacon Status:EVIDENCE, lya Construtora Status:EVIDENCE, City of McMinnville OR Status:DISCLOSED, PCL Holding Status:EVIDENCE, Nichirei Status:DISCLOSED](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/)
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

