Ransomware victim disclosure
← All victimsBlackmon Mooring
Claimed by Hunters · listed 1 year ago
Status timeline
- ListedApr 5, 2025
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Apr 5, 2025
About the victim
AI dossier — public-source company profileBMS CAT is a major US-based disaster recovery and restoration company founded in 1948, headquartered in Fort Worth, Texas. They provide fire, water, mold, and smoke damage restoration, biohazard cleanup, and reconstruction services to residential and commercial clients across 24+ US locations, claiming expertise in large-scale and critical infrastructure recovery.
- Industry
- Disaster Recovery & Restoration Services
- Address
- Fort Worth, Texas, USA (headquarters); 24+ US locations listed
- Founded
- 1948
Attack summary
Severity: high — Confirmed dual exfiltration and encryption of a large operational service company with national infrastructure exposure (disaster recovery, critical facilities, healthcare/education clients). BMS CAT handles sensitive customer data and insurance claims across multiple sectors. No proof count or specific regulated data confirmed, limiting to 'high' rather than 'critical'.The 'hunters' ransomware group claims to have both exfiltrated data and encrypted systems at BMS CAT. No specific data types or operational impact are detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Business operational data
- Insurance claim information
What the group claims
Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

