Ransomware victim disclosure
← All victimsColliers International Idaho
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Mar 9, 2026
- Data size
- 42 GB
About the victim
AI dossier — public-source company profileColliers International Idaho is a commercial real estate services firm operating in Idaho, affiliated with the global Colliers International brand. The company offers brokerage and advisory services for retail, office, medical, and industrial properties available for sale or lease. It caters to a diverse client base across the state of Idaho.
- Industry
- Commercial Real Estate Services
Attack summary
Severity: critical — The disclosed data inventory includes regulated PII at scale (SSNs, passports, DLs), medical information, and financial records affecting employees and potentially clients, meeting the threshold for critical severity under regulated/sensitive data exfiltration.The Akira ransomware group claims to have exfiltrated approximately 42 GB of corporate data from Colliers International Idaho, with imminent publication threatened. The stolen data allegedly includes employee passports, driver's licenses, Social Security numbers, W-9 forms, medical information, financial records, project documents, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security numbers (SSNs)
- W-9 forms
- Medical information
- Financial records
- Project documents
- Non-disclosure agreements (NDAs)
What the group claims
Colliers Idaho specializes in commercial real estate, offering a variety of properties for sale or lease throughout Idaho. Their p ortfolio includes options for retail, office, medical, and indust rial spaces, catering to diverse client needs. We will upload 42gb of corporate data soon. Employee passports, D Ls, SSNs, w9 forms, medical information. Financials, projects, ND As, etc.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

