Ransomware victim disclosure
← All victimsEnvironmental Corporation of America
listed as ECA-USA.COM · Claimed by Cl0p · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileEnvironmental Corporation of America (ECA) is an environmental, ecological, geotechnical, and cultural resources consulting firm headquartered in Alpharetta, Georgia. Founded in 1989, ECA serves public and private sector clients throughout the United States across sectors including telecommunications, commercial real estate, transportation, and state and federal projects. The firm has completed thousands of projects spanning environmental assessments, wetlands delineation, geotechnical studies, and cultural resource reviews.
- Industry
- Environmental & Geotechnical Consulting
- Address
- 1375 Union Hill Industrial Court, Alpharetta, GA 30004
- Founded
- 1989
Attack summary
Severity: high — Data is confirmed published by Cl0p, a prolific ransomware/exfiltration group. ECA handles sensitive government, federal, and municipal project data as well as regulated environmental compliance records, elevating the potential harm of exposure beyond typical business data.Cl0p claims to have attacked Environmental Corporation of America and has published data (disclosed_status: data_published); the leak post provides no specific detail on encryption or exfiltration methods, and no ransom amount or data volume was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Client project files
- Environmental assessment records
- Geotechnical reports
- Cultural resource documentation
- Business correspondence
- Employee records
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteECA-USA.COM
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

