Ransomware victim disclosure
← All victimsGardaWorld
listed as Garda · Claimed by Metaencryptor · listed 2 years ago
Status timeline
- Listed
Dec 7, 2023
- Data leaked
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- Canada
- Sector
- Business Services
- Listed on leak site
- Dec 7, 2023
About the victim
AI dossier — public-source company profileGardaWorld is a major North American private security company headquartered in Canada, providing contract security officers, K9 security, crowd management, and related services across the United States and Canada. The company operates offices in 48 U.S. states and serves sectors including government, healthcare, financial, retail, data centers, and critical infrastructure. It is one of the largest security firms on the continent.
- Industry
- Physical Security Services
- Employees
- 10000+
Attack summary
Severity: high — GardaWorld is a large security services provider serving government, critical infrastructure, financial, and healthcare clients; confirmed data publication by the threat actor involving a company of this sensitivity and scale constitutes high severity, with potential exposure of client contracts, employee PII, and sensitive operational security data.The Metaencryptor ransomware group claims an attack on GardaWorld and has published data (disclosed status: data_published), though the leak post itself is minimal and does not detail specific exfiltration volumes or encryption claims.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Potentially employee records
- Potentially client/contract information
What the group claims
Garda
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
