Ransomware victim disclosure
← All victimsEpcon Communities
Claimed by Payoutsking · listed 2 months ago
Status timeline
- ListedApr 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Payoutsking
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Apr 30, 2026
About the victim
AI dossier — public-source company profileEpcon Communities is a US-based homebuilder and franchisor founded in 1986, headquartered in Dublin, Ohio. It specializes in developing and selling single-story, low-maintenance homes targeting active adults aged 55 and older, and franchises its community development model to builders across the United States.
- Industry
- Residential Real Estate & Homebuilding
- Address
- Dublin, Ohio, US
- Founded
- 1986
Attack summary
Severity: medium — Data published by the group with no public site content available to verify details; lack of proof count or data inventory specifics prevents higher confidence; residential/construction sector presents moderate sensitivity risk.The payoutsking group claims to have compromised Epcon Communities. No details are provided in the available leak post excerpt regarding what data was exfiltrated, encrypted, or the scope of the attack.
Original description
AI-summarised, not from the leak postEpcon Communities is a US-based homebuilding and franchise company founded in 1986 and headquartered in Dublin, Ohio. It specializes in developing and selling single-story, low-maintenance homes primarily targeting active adults aged 55 and older. Operating in the residential real estate and construction industry, Epcon also franchises its community development model to builders across the United States.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

