Ransomware victim disclosure
← All victimsLegendary Home Services
listed as legendsmn (Blue Ox, Paul Bunyan, Lumberjack Electric) · Claimed by Nightspire · listed 2 hours ago
Status timeline
- ListedAug 10, 2026
Current state: Listed for ransom
At a glance
- Group
- Nightspire
- Status
- Listed for ransom
- Country
- United States
- Sector
- Utilities/Energy
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileLegendary Home Services is a Minnesota-based home services company operating under three brand names (Blue Ox Heating & Air, Paul Bunyan Plumbing & Drains, EarlyBird Electric) that provides HVAC, plumbing, and electrical repair, installation, and maintenance services to homeowners across Minneapolis, Rochester, and surrounding Minnesota communities.
- Industry
- Residential HVAC, Plumbing & Electrical Services
- Address
- 5720 International Pkwy, Minneapolis, MN 55428, United States
Attack summary
Severity: medium — Claimed exfiltration of client and vendor data with potential operational impact to a utilities/services provider, but no proof files are currently advertised and data availability is marked as unavailable, reducing confidence in the breach claim.Nightspire claims to have exfiltrated technical data, vendor data, client data, and military facility data from Legendary Home Services. The group lists the victim but indicates 'Data is not available now,' suggesting either the data was removed or the claim is unsubstantiated.
Data the group says was taken
AI dossier — extracted from the leak post- Technical data
- Vendor data
- Client data
- Military facility data
What the group claims
Technical, vendor, client, and military facility data.
The leak post
captured from the group's site### The Nightspire data breach channel is back in operation. Subscribe to stay updated in real-time. - HR & Payroll Data- Financial & Accounting Records- Payment & Credit Card Data- Customer & CRM Data- Orders & Supply Chain Data- SharePoint & Business Application Data - Employee PII- Payroll- Benefits- Financials- Client HR- Identity Docs - Bank account details- Digital certificate- Financial records- Employee/HR records- Customer and supplier data- Contracts and quotations - HR Documents- Financial Documents- Contracts- Bids & Proposals- Project Documents- Office Documents- Construction Standards- Insurance Documents - Executive Data - HR Data and Documents- Data for IT Department - Internal Document- Financial & HR Documents- Design Data - Accounting / Finance Documents- Projects Data, Purchasing / Procurement Documents - Quality / Document Control- Maintenance, and HR documents - Production / Manufacturing Data [Thai Seng International Co. Ltd](https://www.thaiseng.co.th/) - Administration documents from Thaiseng International Co, Ltd- Marketing data which includes client information. Data is not available now. - All Motor Designs- CAD Files- Employee & HR Sensitive Data- Legal…
Data the group says was taken
- Technical Data
- Vendor Data
- Client Data
- Military Facility Data
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

