Ransomware victim disclosure
← All victimsHoy Construction
Claimed by nova · listed 7 hours ago
Status timeline
- Listed
May 22, 2026
- Data leaked
At a glance
- Group
- nova
- Status
- Data leaked
- Sector
- Construction
- Listed on leak site
- May 22, 2026
About the victim
AI dossier — public-source company profileHoy Construction is a 100% employee-owned commercial construction management firm based in Hampton Roads, Virginia, specializing in commercial, industrial, and institutional facilities. They offer design-build services, preconstruction services, and emphasize open-book transparency and cost/schedule management.
- Industry
- Commercial Construction Management
- Address
- Hampton Roads, VA
- Founded
- 1933
Attack summary
Severity: medium — Confirmed data exfiltration claim with offer of proof samples, but no specific sensitive data categories confirmed and no proof files publicly visible in the post.Nova claims to have exfiltrated data from Hoy Construction and is offering to provide samples to the company upon contact with their support department.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Project data
- Client information
- Financial records
What the group claims
Since 1933, Hoy Construction has specialized in commercial construction management for commercial, industrial, and institutional facilities in Hampton Roads, VA. As a 100% employee-owned company, they emphasize a design-build approach, preconstruction services, and open-book transparency. Their experienced team collaborates with owners and architects to effectively manage costs and schedules while delivering high-quality, durable buildings. Hoy Construction is dedicated to building strong partnerships and ensuring accountability and communication throughout the construction process - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
