Ransomware victim disclosure
← All victimsVirtual Projects (virtualprojects.build)
Claimed by J · listed 8 months ago
Status timeline
- Listed
Sep 29, 2025
- Data leaked
At a glance
- Group
- J
- Status
- Data leaked
- Country
- DK
- Sector
- Construction
- Listed on leak site
- Sep 29, 2025
About the victim
AI dossier — public-source company profileVirtual Projects is a BIM management and technology consulting firm serving the construction industry, based in Northern California. The company offers preconstruction, project estimating, construction management, and virtual design and construction (VDC) services. Their website identifies them as 'BIM Managers & Technology Consultants', indicating a specialisation in digital construction methodologies.
- Industry
- BIM Management & Construction Technology Consulting
Attack summary
Severity: high — Data has been published (data_published status confirmed), indicating confirmed exfiltration with actual release of company data. Construction project files and client records likely contain sensitive business and potentially personal information, representing significant business data exposure.Group J claims to have published data exfiltrated from Virtual Projects, with the disclosed status marked as data_published, indicating stolen files have been released. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Business documents
- Project files
- Client data
- Construction management records
Original description
AI-summarised, not from the leak postVirtual Projects is a construction-focused firm based in Northern California. They are dedicated to providing a comprehensive range of services including preconstruction, project estimating, and construction management. Their cutting-edge technology and experienced personnel allow them to offer virtual design and construction methodologies, assisting clients from concept through to completion.
Sources
Source
Indexed 8 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
