Ransomware victim disclosure
← All victimsMcFarlane Agencies
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 20, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileMcFarlane Agencies is an independent insurance brokerage located in Okotoks, Alberta, Canada, operating since 1975. The firm offers a broad range of personal and commercial insurance products including automobile, recreational, farm, acreage, and property insurance, as well as financial services through a partnership with Desjardins Financial Security Investments Inc.
- Industry
- Insurance Brokerage & Financial Services
- Address
- Okotoks, Alberta, Canada
- Founded
- 1975
Attack summary
Severity: critical — The threat actor claims exfiltration of regulated PII at scale — including government-issued identity documents (SSNs, passports, driver's licences) and financial records — from an insurance brokerage whose clients' sensitive personal data is the core asset at risk.Akira claims to have exfiltrated approximately 10 GB of corporate data, including detailed client personal documents (SSNs, passports, driver's licences, addresses, phone numbers), employee information, financial records, client information, and NDAs, with publication described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Social Security Numbers (SSNs)
- Passport copies
- Driver's licence copies
- Client addresses and phone numbers
- Employee information
- Financial records
- Client information
- Non-disclosure agreements (NDAs)
What the group claims
McFarlane Agencies is an independent insurance brokerage located in Okotoks, Alberta, specializing in a wide range of insurance an d financial services since 1975. They offer automobile, recreatio nal, commercial, travel, pet, farm, acreage, and property insuran ce, along with financial services through a partnership with Desj ardins Financial Security Investments Inc. We will upload 10gb of corporate data soon. Detailed clients' per sonal documents (SSNs, passports, DLs, addresses, phones and so o n), employee information, financials, client information, NDAs, e tc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

