Ransomware victim disclosure
← All victimsIntech IMS
listed as intechims.com · Claimed by Threeam · listed 3 years ago
Status timeline
- ListedSep 14, 2023
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Sep 14, 2023
About the victim
AI dossier — public-source company profileIntech IMS (intechims.com) is a contract packaging and fulfillment company based in La Crosse, Wisconsin, specializing in beverage re-packing and fully automated variety packaging services. The company also offers print and promotional products. It serves clients seeking to increase production capacity through outsourced packaging solutions.
- Industry
- Beverage Re-Packing & Fulfillment / Contract Packaging
- Address
- La Crosse, WI, United States
Attack summary
Severity: high — Data has been published by the threat actor (data_published status), confirming exfiltration and public release of company data, which represents significant business data exposure even without a stated data size.The Threeam ransomware group claims to have compromised Intech IMS and has published data (disclosed status: data_published), indicating exfiltration of company data, though no specific data size or ransom demand was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Business operational data
- Client/customer records
- Internal company files
What the group claims
Specializing in Beverage Re-Packing and Fulfillment for just about anything Start increasing your production with our fully automated variety packaging services. We have the bandwidth to quickly...
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

