Ransomware victim disclosure
← All victimsnorthamericansigns.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedMar 27, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 27, 2024
About the victim
AI dossier — public-source company profileNorth American Signs is a full-service commercial signage provider founded in 1934, offering design, project management, manufacturing, and service. Based in South Bend, Indiana, they serve the signage industry.
- Industry
- Commercial Signage Manufacturing
- Address
- 3601 West Lathrop, South Bend, IN 46628, USA
- Founded
- 1934
Attack summary
Severity: high — Confirmed exfiltration of ~250GB across multiple sensitive business categories (accounting, design, CAD), which represents significant operational and financial data exposure for a manufacturing company.BlackBasta claims to have exfiltrated approximately 250GB of company data including office records, accounting files, design files, CAD documents, and user folders. No operational disruption is mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- Office data
- Accounting records
- Design files
- CAD documents
- User folders
What the group claims
North American Signs A commercial signage industry leader, North American Signs is a full-service provider from design and project management to manufacturing and service.SITE: www.northamericansigns.com Address : 3601 West Lathrop South Bend, IN 46628 USAALL DATA SIZE: ~250gb 1. Office data 2. Accounting 3. Design 4. CAD 5. Users folders and files & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

