Ransomware victim disclosure
← All victimsO'Brien Engineering & Architecture
listed as obrieneng.com · Claimed by incransom · listed 1 day ago
Status timeline
- Listed
Jun 5, 2026
- Data leaked
At a glance
- Group
- incransom
- Status
- Data leaked
- Country
- US
- Sector
- Construction
- Listed on leak site
- Jun 5, 2026
About the victim
AI dossier — public-source company profileO'Brien Engineering & Architecture (OEI) is a mission-driven A/E firm founded in 1987, specializing in resilient facility design across horizontal and vertical infrastructure. They serve federal, state, and local sectors with expertise in military installations, healthcare facilities, water infrastructure, and critical facility assets across the U.S. and territories.
- Industry
- Engineering & Architecture Services
- Founded
- 1987
Attack summary
Severity: high — Confirmed exfiltration of confidential government and military project data from a cleared federal contractor. Exposure of NDA-protected materials, military installation designs, and government system references (VA, SAM.gov) constitutes significant operational and security risk to U.S. infrastructure and defense systems.Incransom claims exfiltration of confidential contract documents, NDA materials, and files related to government and military work, including references to VA and SAM.gov credentials or data.
Data the group says was taken
AI dossier — extracted from the leak post- confidential contracts
- NDA documents
- government/military project files
- VA system access/credentials
- SAM.gov records
What the group claims
contract nda confidential gov\dot\military\va\sam.gov other
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
