Ransomware victim disclosure
← All victimsMh Soluciones
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 12, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileMh Soluciones is a Mexican company specializing in outsourcing support and management processes for maintenance and installation businesses. It helps clients improve operational performance through tailored solutions while ensuring transparency and cost control, allowing clients to focus on core activities.
- Industry
- Business Process Outsourcing & Facilities Management
Attack summary
Severity: critical — The exfiltration includes regulated PII at scale (scanned passports and driver's licenses of employees), government contracts, hazardous waste management records, and client data — spanning multiple categories of sensitive and potentially regulated information across 85 GB of disclosed data.Akira claims to have exfiltrated approximately 85 GB of corporate data from Mh Soluciones, including scanned employee identity documents, project documentation related to hazardous waste management and government contracts, agreements, and client information, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Scanned identity documents
- Project documents (hazardous waste management)
- Government contracts
- Business agreements
- Client information
What the group claims
mh SOLUCIONES specializes in outsourcing support and management p rocesses, helping clients enhance performance while ensuring tran sparency and better cost control. The company offers tailored sol utions for maintenance and installation businesses, allowing clie nts to focus on their core operations. We will upload 85gb of corporate data soon. Lots of employee scan ned docs (passports, DLs and so on), project docs (hazardous wast es management, government contracts), agreements, client informat ion.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

