Ransomware victim disclosure
← All victimsMKC Customs Brokers International Inc.
Claimed by Incransom · listed 5 months ago
Status timeline
- ListedJan 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 18, 2026
About the victim
AI dossier — public-source company profileMKC Customs Brokers International Inc. is a customs brokerage firm operating in the United States that facilitates international trade by managing customs clearance and compliance for shipments of varying sizes. The company positions itself as a dependable partner for importers and exporters navigating complex cross-border regulatory requirements. No further detail on scale or headquarters is available from the leak post or a public site.
- Industry
- Customs Brokerage & International Trade Logistics
Attack summary
Severity: high — Data has been confirmed published by the threat actor. As a customs broker, MKC likely holds sensitive trade documents, importer/exporter PII, financial records, and supply chain data for multiple clients, representing significant business and potentially regulated data exposure across international trade transactions.The Incransom group claims to have attacked MKC Customs Brokers International Inc. and has published data (disclosed status: data_published), indicating exfiltration of company data, though the specific volume, nature of files, and whether encryption occurred are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customs brokerage records
- Shipment documentation
- Client trade data
- Business correspondence
What the group claims
International trading has never been as complicated and demanding as it is today. Every shipment, large or small, requires a customs broker who is an absolutely dependable working partner. That's MKC Customs Brokers!
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

