Ransomware victim disclosure
← All victimsModular Technologies Incorporated
listed as MODTECH.CA · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileModular Technologies Incorporated (modtech.ca) is a Canadian managed IT services provider offering IT management and consulting, backup and disaster recovery, monitoring and maintenance, cybersecurity, telephony, and support services. The company serves markets including medical, financial, construction, retail, and non-profit sectors. It is reachable at (403) 279-6380, indicating a Calgary, Alberta base of operations.
- Industry
- Managed IT Services & IT Support
Attack summary
Severity: high — Data is reported as published by Clop, a prolific exfiltration-focused ransomware group. Modular Technologies is an MSP serving medical and financial clients, meaning any exfiltrated data likely includes sensitive client IT data, credentials, and potentially regulated information from downstream clients. MSP compromise inherently poses supply-chain risk.Clop claims to have attacked Modular Technologies Incorporated and has disclosed the victim with a status of 'data_published', suggesting data exfiltration and publication. The leak post itself contained no readable content beyond a queue/redirect placeholder, so specific data categories claimed are not enumerated.
Data the group says was taken
AI dossier — extracted from the leak post- Client data (medical sector)
- Client data (financial sector)
- Business IT environment data
- Potentially managed client credentials or configurations
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

