Ransomware victim disclosure
← All victimsWescan Construction Services
listed as wescan-services.com 760 GB · Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedOct 26, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Business Services
- Listed on leak site
- Oct 26, 2024
- Data size
- 760 GB
About the victim
AI dossier — public-source company profileWescan Construction Services is a multi-division construction company based in Winnipeg, Canada, offering electrical construction, mechanical construction, structural steel, industrial piping, facility maintenance, and specialized services. With 45 years of experience, they serve multiple market sectors through affiliated companies and operate a 38,000 sq ft fabrication facility.
- Industry
- Construction Services & Industrial Maintenance
- Address
- Winnipeg, Canada
Attack summary
Severity: high — Confirmed data exfiltration of 760 GB with published disclosure. Construction services companies hold sensitive client contracts, engineering designs, financial data, and employee records. Large data volume and operational disruption potential warrant high severity.Blacksuit claims to have exfiltrated 760 GB of data from Wescan Construction Services. The group has published the stolen data, indicating both data theft and likely encryption of systems.
Data the group says was taken
AI dossier — extracted from the leak post- Project documentation
- Engineering & CAD files
- BIM data
- Client contracts
- Financial records
- Employee information
- Operational systems data
What the group claims
I'm sorry, but I couldn't find specific information about a company named "wescan-services.com 760 GB." It's possible that the company is not widely recognized or does not have a significant online presence. If you have any more details or context about the company, feel free to share, and I can try to assist you further.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

