Ransomware victim disclosure
← All victimsGraymont
listed as graymont.com · Claimed by Chaos · listed 11 days ago
Status timeline
- ListedJun 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Chaos
- Status
- Data leaked
- Country
- Canada
- Sector
- Manufacturing
- Listed on leak site
- Jun 22, 2026
About the victim
AI dossier — public-source company profileGraymont is a manufacturer of essential calcium-based solutions and applications. The company operates core infrastructure supporting production, distribution, and corporate functions across multiple operational units.
- Industry
- Chemical Manufacturing – Calcium Products
Attack summary
Severity: high — Threat actor claims exfiltration of sensitive business data including executive financial records and full infrastructure access; data has been published; no proof files visible in excerpt but claim credibility is elevated by operational sector and specificity.The Chaos group claims to have gained full access to Graymont's corporate infrastructure and exfiltrated a large volume of sensitive data, including executive financial strategy and other operational information. No specific data categories or volumes are confirmed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- executive financial strategy
- operational data
- corporate infrastructure records
What the group claims
NOTICE: Graymont – Final Warning We have successfully gained full access to the corporate infrastructure of Graymont. Our team currently holds a massive volume of highly sensitive data. The scope of our access covers the entire core of your operations, from executive financial strategy to individ…
Sources
Source
Indexed 11 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

