Ransomware victim disclosure
← All victimsPriceTable
Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 28, 2026
About the victim
AI dossier — public-source company profilePriceTable (pricetable.io) is a US-based SaaS company providing field service management software for trade contractors such as painters, landscapers, electricians, plumbers, and HVAC technicians. The platform offers invoicing, quoting, job scheduling, customer portals, and payment processing integrated with Stripe and QuickBooks Online. It is trusted by hundreds of trade professionals and positions itself as an all-in-one business operations tool for small contractors.
- Industry
- Field Service Management Software (SaaS)
Attack summary
Severity: medium — Data is listed as published by the group, implying some level of exfiltration claim, but the leak post is empty of detail, proof, or specific data categories. PriceTable is a SaaS platform that likely holds contractor and customer business data (invoices, contacts, payment references), which carries moderate sensitivity. Absence of evidence of regulated PII at scale or operational disruption caps severity at medium.The Nightspire ransomware group claims to have attacked PriceTable and lists the disclosure status as data_published; however, the leak post contains no detail on whether data was encrypted or exfiltrated, and no specific data categories or proof files are described.
What the group claims
Data is not available now.
Sources
- Victim sitepricetable.io
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

