Ransomware victim disclosure
← All victimsCannavative Group
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 22, 2026
About the victim
AI dossier — public-source company profileCannavative Group is a Nevada-based cannabis company that grows, refines, and manufactures marijuana products including pre-rolls, edibles, concentrates, and cartridges. The company operates retail locations in Las Vegas, Reno, and Carson City, Nevada. It markets itself as a producer of high-quality, locally grown cannabis products.
- Industry
- Cannabis Products Manufacturing & Retail
- Address
- Las Vegas, Nevada, United States
Attack summary
Severity: high — Confirmed exfiltration and publication of data including regulated cannabis-tracking database (METRC, a government-mandated seed-to-sale compliance system), financial records, and personally identifiable employee and client documents, representing significant regulatory and privacy exposure.The Nightspire ransomware group claims to have exfiltrated data from Cannavative Group, including QuickBooks financial files, METRC cannabis compliance database records, and employment and client documents. The disclosed status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- QuickBooks financial files
- METRC cannabis compliance database
- Employee documents
- Client documents
What the group claims
- QuickBook Files- METRC DB-Employeement & Clients Documents
Sources
- Victim sitewww.cannavativegroup.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

