Ransomware victim disclosure
← All victimsArban & Carosi
Claimed by incransom · listed 21 days ago
Status timeline
- Listed
Apr 30, 2026
- Data leaked
At a glance
- Group
- incransom
- Status
- Data leaked
- Country
- US
- Sector
- Business Services
- Listed on leak site
- Apr 30, 2026
About the victim
AI dossier — public-source company profileArban & Carosi appears to be a US-based architecture or engineering firm operating in the business services sector. Based on the leak post, the company holds detailed building plans, including those for US Army facilities, suggesting involvement in government and defence-related construction or design projects. No public site was available to confirm further operational details.
- Industry
- Architecture & Engineering Services
Attack summary
Severity: critical — The exfiltration includes sensitive PII at scale, financial records, and — critically — detailed architectural plans of US Army buildings, which constitutes potential exposure of defence/government infrastructure data, elevating this to critical severity.The incransom group claims to have exfiltrated approximately 1TB of data including employee PII, financial documentation, customer records, internal correspondence, and detailed architectural plans of buildings including US Army facilities, with a stated intent to publish all data within one week.
Data the group says was taken
AI dossier — extracted from the leak post- Employee names and positions
- Personal and work email addresses
- Employee phone numbers
- Contracts
- Invoices
- Revenue data
- Customer contact details
- Project details
- Internal service emails
- Internal process documentation
- Company plans and strategy documents
- Detailed architectural/building plans
- US Army building plans
What the group claims
Arban Carosi: 1TB customer and company data leaked due to negligence. * * Full employee base: Including names, positions, personal and work email addresses, phone numbers. * * Financial Documentation: Contracts, Invoices, Revenue Data * * Customer base: Customer contact details, project details * * Internal correspondence: Service emails and documents disclosing internal processes and company plans. !! In the screenshots, you can see that we have accessed detailed plans of various buildings, including U.S. Army buildings!! We will publish all the data in a week and everyone can use it for their own purposes.
Sources
Source
Indexed 21 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
