Ransomware victim disclosure
← All victimsKologik (operating as Coreforce)
listed as Kologik · Claimed by Snatch · listed 3 years ago
Status timeline
- ListedNov 29, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Nov 29, 2023
About the victim
AI dossier — public-source company profileKologik, operating under the Coreforce brand, is a U.S.-based public safety technology company providing an integrated suite of software and hardware solutions for law enforcement, corrections, emergency response, and justice agencies. Its platform spans computer-aided dispatch (CAD), records management (RMS), jail management, body-worn cameras, in-vehicle video, ALPR, and digital evidence management. The company processes over 500 TB of data and 2.1 million incidents per month across its customer base.
- Industry
- Public Safety Technology
Attack summary
Severity: critical — Kologik/Coreforce handles highly sensitive public safety data for law enforcement, corrections, and justice agencies — including criminal records, incident data, digital evidence, inmate records, and chain-of-custody information. A confirmed exfiltration and publication event against a vendor processing this volume of regulated government/law enforcement PII at scale constitutes a critical severity incident, with downstream risk to multiple agencies and individuals.The Snatch ransomware group claims to have exfiltrated data from Kologik/Coreforce and has published it ('data_published' status), naming specific senior executives including the CFO, President, Chief Architect, and multiple VPs along with their contact details as persons responsible for the leak. No ransom amount or total data size was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Executive contact information (names, titles, emails, phone numbers)
- Internal organizational data
- Potentially law enforcement agency operational data
- Potentially criminal records and incident data
- Potentially digital evidence files
- Potentially corrections/inmate records
What the group claims
More information in our telegram channel https://t.me/snatch_team Persons responsible for data leakage:Teri Jones:CFO[email protected];Ben Balvin:Chief Architect[email protected];Matthew Follis:CFO, Financial Officer+1 972-839-9511[email protected];Aubrey Wardwell:VP+1 804-986-3318[email protected];Matt Chism:President, President, Sales, VP, VP, Sales[email protected];Rob Powell:Manager, Manager, Operations, Service Manager, Technical Service Manager, VP+1 225-291-5440[email protected];Sean Murphy:VP, VP, Product Development+1 225-291-5440[email protected];Melanie Smith:Director,
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

