Ransomware victim disclosure
← All victimsnathcompanies.com
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedOct 29, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Hospitality and Tourism
- Listed on leak site
- Oct 29, 2024
About the victim
AI dossier — public-source company profileNath Companies is a diversified management firm based in Bloomington, Minnesota, with over 50 years of combined experience. The company owns and operates hotels (12 properties across 5 brands including DoubleTree, Embassy Suites, and Crowne Plaza), manages restaurants (150+ locations across 6 states), and manages real estate portfolios including apartments and commercial properties.
- Industry
- Hospitality Management & Real Estate
- Address
- 900 American Blvd East Suite 300, Bloomington, MN 55420
Attack summary
Severity: medium — Confirmed data publication by ransomware group targeting a company with significant operational footprint (150+ restaurants, 12 hotels, real estate portfolio); however, no specific regulated data categories (PII, financial records, payment systems) are confirmed in the available disclosure, and no quantified data volume is stated.Blacksuit claims to have breached Nath Companies and exfiltrated data; the group has published data but the specific nature of exfiltrated files and scope are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- property management data
- operational files
What the group claims
[IA generated] Nath Companies is a diversified business group engaged in hospitality, real estate, and development sectors. The company operates hotels, restaurants, and offers management services. It focuses on delivering quality service and creating value in its ventures. With a commitment to excellence and innovation, Nath Companies aims to enhance customer experiences and expand its market presence.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

