Ransomware victim disclosure
← All victimsHandyTrac
listed as HandyTrac (Greystar Litchfield Park, AZ) · Claimed by ShadowByt3$ · listed 1 day ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- ShadowByt3$
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileHandyTrac is a key control and property management software solution based in Litchfield Park, Arizona. The company provides digital access management and property intelligence systems for managing physical and digital keys across properties.
- Industry
- Property Management & Key Control Systems
- Address
- Litchfield Park, AZ, US
Attack summary
Severity: high — Confirmed exfiltration of employee credentials, financial records, and administrative access controls. Exposure of key control system vulnerabilities and property intelligence data presents significant operational and security risk to the company and its clients' properties.ShadowByt3$ claims to have exfiltrated multiple categories of sensitive data including property intelligence logs, employee credentials, financial records, and administrative access. The group claims to have stolen physical-to-digital key maps and control system data, with one proof file advertised on their leak site.
Data the group says was taken
AI dossier — extracted from the leak post- Physical-to-Digital Key Maps
- Property Intelligence & Vulnerability Logs
- Employee Identity & Credential Data
- Financial Records
- Vendor Records
- Administrative Portal Access
The group's post references roughly 1 proof file.
What the group claims
We have access to sensitive data. It's in your best interest to contact us and negotiate since it will just hurt you if you don't. We stole a lot of sensitive info including the following: - Physical-to-Digital Key Maps (Reports) - Property Intelligence & Vulnerability Logs (HandyTrac Key Control.pdf) - Employee Identity & Credential Data (Employees) - Financial & Vendor Records (Open_and_closed_Invoices) - Administrative Portal Control (Dashboard / Administration) This is not a joke or a bluff it's a sign of a corporate disaster. Figure it out and negotiate and the picture for proof is on are site at the below url: http://sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion/Screenshot_proof.png As you can see negotiate within 72 hours or we will leak the full data.
Sources
- Victim sitenew.handytrac.com
- Leak posthttps://mega.nz
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

