Ransomware victim disclosure
← All victimsService Alimentaire 2000 Inc.
listed as SA2000.COM · Claimed by stormous · listed 7 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileService Alimentaire 2000 Inc. is a Quebec-based company specializing in repair and maintenance of commercial kitchen equipment across all major brands, including steam, gas, and electric appliances. They also sell parts and offer personalized repair services to food service businesses.
- Industry
- Commercial Kitchen Equipment Repair & Sales
Attack summary
Severity: high — Confirmed exfiltration of 150 GB including financial records, banking information, customer data, employee records, and shareholder information. Data has been published. This represents significant business and personal data exposure affecting multiple stakeholder categories.Stormous claims to have exfiltrated approximately 150 GB of data from the company, including financial records, invoices, banking information, customer data, supplier information, and employee records. The group states the data has been published and indicates ongoing extortion communication.
Data the group says was taken
AI dossier — extracted from the leak post- accounting records
- purchase invoices
- accounts payable
- modified invoices
- banking information
- customer payments
- customer lists and purchase orders
- supplier and transporter details
- employee records and hiring documents
- shareholder information
- email and business documents
What the group claims
150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS ***.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company's !
Sources
- Victim siteSA2000.COM
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
