Ransomware victim disclosure
← All victimsMulholland
listed as mulholland.com · Claimed by BrainCipher · listed 3 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 29, 2026
About the victim
AI dossier — public-source company profileMulholland is a leading industrial and environmental services company serving energy, construction, industrial, and government customers across North America. They provide hydro excavation, municipal services, industrial cleaning, logistics, and specialized support to the energy sector and critical infrastructure projects.
- Industry
- Industrial & Environmental Services
- Address
- 10308 W County Rd 72, Midland, TX 79707
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data including PII at scale (employee medical records, drug tests, banking/ACH details), customer financial information, and operational data from energy sector clients. Medical records and banking information are subject to HIPAA and financial regulations respectively.BrainCipher claims to have exfiltrated over 110,900 files totaling 100+ GB. The group alleges access to employee records including drug test results and FMCSA inspection histories, medical/injury records, customer contracts and banking details, operational data including GPS telemetry and rig information, and regulatory documents.
Data the group says was taken
AI dossier — extracted from the leak post- Employee driver folders with drug test records
- FMCSA inspection history
- Medical and injury records
- Master Service Agreements (MSAs) and NDAs
- Customer W-9 forms and credit applications
- ACH forms and banking details
- Rate and billing information
- GPS telemetry data
- Daily rig operational data
- Permit documents (hazardous waste, DOT, airport)
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteWe have 110900 files with a total size of over 100 GB. The data includes: 1)Personal driver folders with confidential drugs test records and FMCSA inspection history; 2)Medical data and injury records; 3)MSAs/NDAs with major customers (E&P: Continental Resources, OXY, Chord, Baytex, etc); 4)Customer W-9, credit applications, and ACH forms — counteragent banking details and account information; 5)Rates/billing (volumes, revenue); 6)GPS telemetry;7)Daily rig data (North American Rig Data); 8)Permit documents (Arkansas Haz Waste Permit, DOT audits, OCC/DFW Airport); If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: October 7, 2026 at 13:00
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

