Ransomware victim disclosure
← All victimsCirculating Air
Claimed by VYPR · listed 10 hours ago
Status timeline
- ListedOct 5, 2026
- Data leakeddate unknown
At a glance
- Group
- VYPR
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Oct 5, 2026
About the victim
AI dossier — public-source company profileCirculating Air, Inc. is a Los Angeles-based HVAC contractor founded in 1965, specializing in commercial and residential heating, cooling, and air quality systems. With 150+ employees and 60 years of operations, they serve major clients including UCLA, LAUSD, and Westfield Shopping Centers across the Los Angeles region.
- Industry
- HVAC Services (Commercial & Residential)
- Address
- Los Angeles, CA, USA
- Employees
- 150
- Founded
- 1965
Attack summary
Severity: low — No proof files, screenshots, or specific data inventory advertised in the leak post. No operational impact or data types confirmed. Only listing/announcement.VYPR claims to have accessed Circulating Air's systems and published data. The leak post does not specify what data was exfiltrated or whether systems were encrypted.
What the group claims
Circulating Air, Inc. specializes in HVAC services in Los Angeles and surrounding areas, offering quality repair, installation, and maintenance for heating and cooling systems. They provide a comprehensive range of services including air conditioning, heating, indoor air quality, and commercial HVAC solutions. The company caters to both residential and commercial clients, ensuring efficient and reliable service for various HVAC systems. With a commitment to customer satisfaction, Circulating Air, Inc. is dedicated to improving indoor comfort and air quality.
Sources
- Victim sitewww.circulatingair.com
Source
Indexed 10 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

