Ransomware victim disclosure
← All victimsEDF Mission Critical Group
listed as EDF Group · Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Jan 22, 2026
About the victim
AI dossier — public-source company profileEDF Mission Critical Group is a US-based Schneider Electric Advanced Solutions and Certified Service Sales Partner specializing in mission critical infrastructure solutions for data centers, healthcare, and industrial facilities. Their offerings include critical power, precision cooling, monitoring and management, power distribution, electrical testing and modernization, and design and consulting services.
- Industry
- Mission Critical Infrastructure Solutions & Services
Attack summary
Severity: high — Data has been published (not merely listed), and the victim operates in mission critical infrastructure serving data centers and healthcare facilities, making any data exposure potentially significant for both business and operational security. No specific data inventory is confirmed but the published status elevates severity.The Qilin ransomware group claims to have attacked EDF Mission Critical Group and has published data (disclosed status: data_published), though the specific nature of exfiltrated data and volume have not been stated in the leak post excerpt.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

