Ransomware victim disclosure
← All victimslya Construtora
Claimed by Ransomhouse · listed 2 hours ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Sector
- Construction
- Listed on leak site
- Sep 5, 2026
About the victim
AI dossier — public-source company profileIlya Construtora is a construction company. Limited information is available from the leak post.
- Industry
- Construction
Attack summary
Severity: medium — The group claims evidence status and inclusion in a public disclosure list, but the leak post does not specify what data was exfiltrated, the scale of exposure, or operational impact. The evidence tag suggests proof exists but has not been described.Ransomhouse claims to have compromised Ilya Construtora and lists the victim with 'EVIDENCE' status, indicating the group possesses proof of the breach, though specific details of exfiltration or encryption are not disclosed in this excerpt.
The leak post
captured from the group's siteBelow is a list of companies that either have considered their financial gain to be above the interests of their partners / individuals who have entrusted their data to them or have chosen to conceal the fact that they have been compromised. [Jiangsu Zenergy Battery Technologies Group Co., Ltd. ](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/r/dc227a632118c7c3f9c1e30d3715c607390ee1ae) [Ma Pak Leung Company Limited ](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/r/08394e9fad8016695748ec838b6874bc2d0a8824) [ REXT Holdings Co., Ltd. Status:EVIDENCE, TECHVENTURES BANK S.A. Status:EVIDENCE, City of Beacon Status:EVIDENCE, lya Construtora Status:EVIDENCE, City of McMinnville OR Status:DISCLOSED, PCL Holding Status:EVIDENCE, Nichirei Status:DISCLOSED](http://zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion/)
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

