Ransomware victim disclosure
← All victimsCirrus Aviation Services
listed as cirrusaviation · Claimed by Incransom · listed 5 months ago
Status timeline
- ListedJan 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 16, 2026
- Data size
- 100 GB
About the victim
AI dossier — public-source company profileCirrus Aviation Services is described as the largest luxury private jet charter service in Las Vegas, Nevada. The company operates in the private aviation sector, providing charter flights and related services to clients. No additional detail from a public site was available.
- Industry
- Luxury Private Jet Charter Services
- Address
- Las Vegas, Nevada, United States
Attack summary
Severity: high — 100 GB of confirmed exfiltrated data has been published, encompassing client PII, financial records including all transactions, NDAs, and business agreements — representing significant business-sensitive and potentially regulated personal data at scale in a high-value luxury services context.Incransom claims to have exfiltrated 100 GB of data from Cirrus Aviation Services, including client records, financial databases and transaction records, NDAs, business agreements, and other confidential corporate documents, with the data stated as published.
Data the group says was taken
AI dossier — extracted from the leak post- Confidential documents
- Client data
- NDAs
- Financial data
- Operations data
- Corporate data
- Business agreements
- Development data
- Financial databases
- Transaction records
What the group claims
Cirrus Aviation Services is the largest luxury private jet charter service in Las Vegas. Laek: 100GB WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

