Ransomware victim disclosure
← All victimsregencycenters
Claimed by Iah6477 · listed 18 hours ago
Status timeline
- ListedAug 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Iah6477
- Status
- Data leaked
- Country
- United States
- Sector
- Retail & E-Commerce
- Listed on leak site
- Aug 20, 2026
About the victim
AI dossier — public-source company profileRegency Centers is a publicly traded REIT that owns, operates, and develops shopping centers across the United States. The company manages 485 retail centers totaling over 59 million square feet, primarily located in suburban markets with strong demographics. Regency is S&P 500–listed and focuses on grocery-anchored and mixed-use retail properties nationwide.
- Industry
- Real Estate Investment Trust (REIT) – Shopping Centers
Attack summary
Severity: high — Confirmed exfiltration of a very large dataset (219.5 GiB, ~109k files) from a major S&P 500 REIT; likely contains sensitive operational, financial, tenant, and property-management data. Scale and breadth of data extraction indicate significant business exposure, even though specific data categories are not itemized in the post.The threat actor claims to have exfiltrated data from Regency Centers and is publishing it across four file segments totaling 219.5 GiB (approximately 108,863 files). The post does not specify the nature of the exfiltrated data or confirm encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate/business records
- Operational files
- Property data
- Tenant/customer information
What the group claims
Size: 219.5 GiB
The leak post
captured from the group's sitehosted until · 29d 23h left download everything · 4 parts (each opens on its own): * * * * 2 folder(s) · 108863 file(s) · 219.5 GiB
Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

