Ransomware victim disclosure
← All victimsThe Midland Theatre
Claimed by Akira · listed 5 days ago
Status timeline
- ListedJun 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jun 10, 2026
About the victim
AI dossier — public-source company profileThe Midland Theatre is a historic venue in Newark, Ohio, established in December 1928. It hosts a diverse range of programming including family-friendly events, holiday specials, and performances across multiple genres, drawing tens of thousands of visitors annually.
- Industry
- Performing Arts & Entertainment Venues
- Address
- Newark, Ohio, USA
- Founded
- 1928
Attack summary
Severity: high — Confirmed exfiltration of multiple sensitive data categories including PII (employee W-9s and personal info), financial data, credit cards, and client/guest information. Data has been published per disclosed status. Operational disruption to a cultural institution.The akira group claims to have exfiltrated corporate data including employee personal information (W-9 forms and other documents), financial records, credit card data, client/partner/guest information, and NDAs. The group states intent to publish this data.
Data the group says was taken
AI dossier — extracted from the leak post- Employee W-9 forms
- Employee personal information
- Financial records
- Credit card data
- Client information
- Partner information
- Guest information
- NDAs and contracts
What the group claims
The Midland Theatre originally opened in December of 1928 in Newark, Ohio. The theatre draws te ns of thousands of visitors each year to a wide array of programming from family-friendly event s and holiday specials to top artists in every genre. We will upload corporate data soon. Employee personal information (w-9 forms and other docs), f inancials, credit cards, client, partners and guests information, NDAs, etc.
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

