Ransomware victim disclosure
← All victimsEllisDon Corporation
Claimed by Metaencryptor · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- Canada
- Sector
- Professional Services
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profileEllisDon Corporation is a 100% employee-owned Canadian construction and infrastructure services company founded in 1951. With over 10,000 employees, it provides construction management, engineering, project development, and facilities management across healthcare, transportation, commercial, industrial, government, and defense sectors, operating domestically and internationally.
- Industry
- Construction & Infrastructure Services
- Employees
- 10000+
- Founded
- 1951
Attack summary
Severity: medium — Victim listing with no disclosed proof files, no confirmed data exfiltration details, and no stated operational impact. Company handles government and defense infrastructure contracts, elevating potential sensitivity if breach is confirmed, but evidence remains absent.The metaencryptor group claims to have compromised EllisDon Corporation. The leak post does not specify the attack vector (encryption vs. exfiltration), data categories at risk, or any proof of data breach.
What the group claims
EllisDon Corporation is a leading Canadian construction and infrastructure services company. Founded in 1951, the company provides construction management, engineering, project development, and facilities management services across a wide range of sectors, including healthcare, transportation, commercial, industrial, government, and defense infrastructure. EllisDon operates across Canada and internationally.
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

