Ransomware victim disclosure
← All victimscreativeenvironments.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedMar 12, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Mar 12, 2024
About the victim
AI dossier — public-source company profileCreative Environments is a luxury landscaping and pool design company based in Tempe, Arizona, operating for over 75 years. They provide residential and commercial outdoor living solutions including custom pools, landscape architecture, outdoor kitchens, and hardscaping across Arizona.
- Industry
- Luxury Landscaping & Pool Design
- Address
- 8920 S Hardy Dr, Tempe, Arizona, 85284, United States
- Founded
- 1948
Attack summary
Severity: high — Confirmed exfiltration of 2.5 TB of data including HR records, payroll, customer files, and personal folders. Exposure of employee PII (HR/payroll) combined with customer data at significant scale constitutes high severity.BlackBasta claims to have exfiltrated approximately 2.5 TB of data including accounts, customer files, human resources records, personal user folders, and payroll information from Creative Environments.
Data the group says was taken
AI dossier — extracted from the leak post- User accounts
- Customer files
- Human resources records
- Personal user folders
- Payroll data
What the group claims
Creative Environments prides itself in providing cutting-edge professional landscape design services for residential and commercial setting. We build quality outdoor living environments and ensure on-time production, while remaining committed to customer service and customer satisfaction.SITE: www.creativeenvironments.com Address : 8920 S Hardy Dr, Tempe, Arizona, 85284, United StatesPhone Number. (480) 777-9305ALL DATA SIZE: ~2.5tb 1. Accounts 2. Customer Files 3. Human Recources 4. Personal users folders 5. Payroll & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

