Ransomware victim disclosure
← All victimscipher.systems
Claimed by M3Rx · listed 5 hours ago
Status timeline
- ListedSep 26, 2026
- Data leakeddate unknown
At a glance
- Group
- M3Rx
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Sep 26, 2026
About the victim
AI dossier — public-source company profileCipher Systems is an IT solutions and cybersecurity services firm offering enterprise-grade services including cloud infrastructure, cybersecurity, software engineering, AI & data science, and IT consulting. Based in the US (phone area code 703 suggests Virginia), they serve businesses undergoing digital transformation.
- Industry
- IT Consulting & Cybersecurity Services
Attack summary
Severity: medium — Data exfiltration is claimed (status: 'data_published') but the leak post contains no proof files, screenshots, or specific inventory of what was taken. The vague nature of the disclosure and lack of public proof reduce confidence in the breach claim, though the victim is a cybersecurity firm whose compromise would be operationally significant.The m3rx group claims to have compromised Cipher Systems and offers access to exfiltrated data. The leak post provides minimal detail on the scope or nature of data taken, stating only 'If you are interested in this data, please contact our support' with a Tox contact ID.
What the group claims
+1 703-672-0051 , At Cipher Systems, we specialize in delivering enterprise-grade IT solutions designed to help businesses evolve, secure, and scale in a rapidly changing digital world. From future-proof cloud infrastructures to next-gen cybersecurity and AI-powered intelligence, our solutions are engineered for performance and built for growth. With deep expertise in software engineering, IT consulting, and data science, we turn complex challenges into streamlined outcomes—ensuring that your systems are secure, your data is insightful, and your technology is always a step ahead. Stolen: --
The leak post
captured from the group's siteIf you are interested in this data, please contact our support.Tox: 9A1217BEDA4AB77052A25D17CB6FFB34AFA2BE462E607F2FD8E1DF1DDD4CA16A64E18B1A0BF2
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

