Ransomware victim disclosure
← All victimsUnited Quality Cooperative
Claimed by INC Ransom · listed 5 days ago
Status timeline
- Listed
May 27, 2026
- Data leaked
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- US
- Sector
- Agriculture/Energy
- Listed on leak site
- May 27, 2026
- Data size
- 20 TB
- Records
- 20 files
About the victim
AI dossier — public-source company profileUnited Quality Cooperative is an agricultural and energy services cooperative based in the US that provides bulk fuel, propane, lubricants, and agricultural products including grain handling and retail services through multiple locations.
- Industry
- Agriculture & Energy Distribution
Attack summary
Severity: high — Confirmed exfiltration of multiple data categories including financial documents and employee PII at scale, combined with operational encryption and explicit publication threat.INC Ransom claims to have encrypted United Quality Cooperative's systems and exfiltrated internal corporate correspondence, financial documents, and employee personal data. The group threatened to publish all stolen information within one week if ransom was not paid.
Data the group says was taken
AI dossier — extracted from the leak post- Internal corporate correspondence
- Financial documents
- Employee personal data
The group's post references roughly 34 proof files.
What the group claims
United Quality Cooperative provides a range of services including bulk fuel, propane, lubricants, and agricultural products. Stolen information includes internal corporate correspondence, financial documents, personal data of company employees and more.
The leak post
captured from the group's site```
{"type":true,"message":"Success: got announcements.","payload":{"length":709,"announcements":[{"_id":"69eeb5488f1d14b74359d4c5","company":{"company_name":"United Quality Cooperative / www.uqcoop.com","country":"US","revenue":33800000},"categories":["Encrypted","Proof"],"description":["United%20Quality%20Cooperative%20provides%20a%20range%20of%20services%20including%20bulk%20fuel%2C%20propane%2C%20lubricants%2C%20and%20agricultural%20products.%0D","%0D","We%20have%20at%20our%20disposal%20internal%20corporate%20correspondence%2C%20financial%20documents%2C%20personal%20data%20of%20company%20employees%20and%20much%20more.%0D","%0D","All%20stolen%20information%20will%20be%20published%20in%20the%20public%20domain%20in%20a%20week%2C%20if%20the%20company's%20management%20does%20not%20pay."],"logo":"69eeb5488f1d14b74359d4a0","proof":["69eeb5488f1d14b74359d47e","69eeb5488f1d14b74359d47f","69eeb5488f1d14b74359d480","69eeb5488f1d14b74359d481","69eeb5488f1d14b74359d482","69eeb5488f1d14b74359d483","69eeb5488f1d14b74359d484","69eeb5488f1d14b74359d485","69eeb5488f1d14b74359d486","69eeb5488f1d14b74359d487","69eeb5488f1d14b74359d488","69eeb5488f1d14b74359d489","69eeb5488f1d14b74359d48a","69eeb54…Data the group says was taken
- internal corporate correspondence
- financial documents
- personal data
Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
