Ransomware victim disclosure
← All victimsAssociated Asset Management
listed as AAM:HOA Management · Claimed by Direwolf · listed 2 days ago
Status timeline
- ListedAug 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 15, 2026
About the victim
AI dossier — public-source company profileAssociated Asset Management (AAM) is a US-based homeowners association and community association management company headquartered in Arizona. The company provides comprehensive HOA management services including resident record management, accounting, architectural reviews, and operates recreation and gate-access platforms serving multiple states (Arizona, South Carolina, California).
- Industry
- HOA & Community Association Management
- Address
- Arizona, US
- Employees
- 51-200
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated PII including resident names, addresses, phone numbers, email addresses, and dates of birth across multiple databases. Includes financial data (delinquency, payment card transaction logs, general ledger), tenant personal information with lease details, employee credentials and payroll data, and board member contact information. The breadth and sensitivity of data combined with the scale (34 GB, 400K+ resident records) meets critical threshold.The direwolf group claims to have exfiltrated 34 GB of data across 432 files from AAM's systems, including encrypted and unencrypted databases from multiple production and staging environments. The breach exposes resident personal information, financial records, delinquency data, architectural records, payment information, employee data, and tenant registration details.
Data the group says was taken
AI dossier — extracted from the leak post- Resident names, addresses, phone numbers, emails, and zip codes
- Delinquency records with payment aging (30/60/90 days)
- HOA general ledger and accounting data (debits, credits, balances)
- Vendor payment details and invoices
- Financial transactions and payment methods (card data, hashes)
- Board committee member contact information
- Architectural review requests and approvals
- Recreation/gate-access POS orders, fees, and transactions
- Employee payroll, time logs, AD credentials, and hiring dates
- Tenant registration with lease information, payment logs, and emergency contacts
- Mobile app user credentials (passwords with salt)
- Email tracking and SendGrid status logs
What the group claims
HOA Management
The leak post
captured from the group's site| (US homeowners-association / community association management company, AZ-based: resident & delinquency records, HOA accounting, architectural reviews, recreation & gate-access platform "eTrak", resale and tenant registration) | | --- | | 34.0 GB, 432 files, , ~ | | HOA management staging: delinquency, residents, GL, vendors | | --- | | HOA reporting warehouse: residents, delinquency, architecture, commerce | | Recreation / gate-access POS: orders, fees, users, payments | | eTrak staging: users, orders, backups, Lexington data | | Resident mobile app: directories, app users, forms, notifications | | eTrak QA environment: users, orders, transactions | | Workforce weekly time logs and employee notifications | | SharePoint-derived task lists and financial review tasks | | Rental / tenant registration with leases and payments | | Metabase built-in sample data (excluded below) | ### 3.1 AAMStaging (SQL Server; HOA community management staging) | **995,603 / 251,858 / 64,203 / 150,207** | Delinquency summaries (lot, unit address, balance, 30/60/90 aging), delinquency details (Demand Fee / Notice of Lien, property names), collection records, …
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

