Ransomware victim disclosure
← All victimsPueblo Mechanical & Controls
Claimed by Nokoyawa · listed 3 years ago
Status timeline
- Listed
May 23, 2023
- Data leaked
At a glance
- Group
- Nokoyawa
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- May 23, 2023
About the victim
AI dossier — public-source company profilePueblo Mechanical & Controls is a leading commercial HVAC, plumbing, and controls systems contractor operating across the Sun Belt and Rocky Mountain regions of the United States, headquartered in Phoenix, Arizona. Founded in 2001, the company serves commercial, industrial, K-12 education, higher education, healthcare, federal, and municipal clients. It operates as a subsidiary of Modigent, a national mechanical services platform, and has been recognized as a top mechanical contractor in Arizona.
- Industry
- Commercial HVAC, Plumbing & Controls Contracting
- Address
- Phoenix, AZ, United States
- Employees
- 201-500
- Founded
- 2001
Attack summary
Severity: high — Data has been published (disclosed status: data_published), confirming exfiltration. The company serves government, healthcare, and educational clients, meaning stolen data likely includes sensitive project, personnel, and potentially regulated client information at meaningful scale.The Nokoyawa ransomware group claims to have attacked Pueblo Mechanical & Controls and has published data from the victim, indicating exfiltration of company data. No ransom amount was stated and no specific data size was disclosed.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Client/customer data
- Employee information
- Project and contract documents
- Financial records
What the group claims
Pueblo Mechanical & Controls is a leading provider of commercial HVAC and plumbing repair, replacement, and retrofit services across the Sun Belt and Rocky Mountain regions of the US. Founded in 2001, the company primarily focuses on servicing customers in commercial, industrial, education...
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
