Ransomware victim disclosure
← All victimsJT-ATFP, LLC
Claimed by Nightspire · listed 2 months ago
Status timeline
- ListedMar 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 31, 2026
About the victim
AI dossier — public-source company profileJT-ATFP, LLC appears to be a U.S.-based defense contractor specializing in Anti-Terrorism/Force Protection (ATFP) services, based on its name and the nature of the claimed stolen data including DOD projects and vulnerability assessments. The company likely provides security consulting, risk assessment, or physical security planning services to Department of Defense or federal government clients. No public website content was available to further verify operational details.
- Industry
- Defense Contracting & Force Protection Services
Attack summary
Severity: critical — The exfiltrated data includes classified contracts, DOD project files, FOUO materials, and vulnerability assessment documents — all of which constitute sensitive national security and regulated government information. Combined with employee PII and confirmed data publication, this represents a critical disclosure with potential national security implications.The Nightspire ransomware group claims to have exfiltrated sensitive data from JT-ATFP, LLC, with the disclosure status indicating data has been published. The claimed stolen data includes classified contracts, DOD project files, vulnerability assessment documents, FOUO (For Official Use Only) files, and employee information.
Data the group says was taken
AI dossier — extracted from the leak post- Classified contracts
- Employee information
- ATFP project files
- Vulnerability assessment documents
- FOUO (For Official Use Only) files
- DOD project files
What the group claims
- Classified Contracts- Employee Information- ATFP Projects- Vulnerability Assessment Docs- FOUO Files- DOD Projects
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

