Ransomware victim disclosure
← All victimsServiceMaster Services, Inc.
listed as ServiceMaster Clean services · Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileServiceMaster Services, Inc. is a privately owned commercial contract cleaning company founded in 1974 and headquartered in Memphis, Tennessee. The company specializes in servicing office buildings and other large facilities under commercial contracts.
- Industry
- Commercial Contract Cleaning Services
- Address
- Memphis, Tennessee, US
- Founded
- 1974
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale, including SSNs, passports, and driver's licenses for approximately 20+ employees, alongside financial and client data — meeting the threshold for critical due to the presence of government-issued identity documents and SSNs.Akira claims to have exfiltrated corporate data including employee personal documents (passports, driver's licenses, SSNs), financial records, contracts and agreements, and client files, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security Numbers (SSNs)
- Financial records
- Contracts and agreements
- Client files
What the group claims
ServiceMaster Services, Inc. is a privately owned and operated co mmercial contract cleaning company. Founded in 1974, ServiceMaste r specializes on servicing office buildings and other large facil ities. It is headquartered in Memphis, Tennessee. We will upload corporate data soon. Personal data of employees (p assports, 20 DLs, SSNs and others), financials, contracts and ag reements, client files, and so on.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

