Ransomware victim disclosure
← All victimsTruGreen
listed as trugreen.com · Claimed by Incransom · listed 2 months ago
Status timeline
- ListedApr 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Apr 22, 2026
About the victim
AI dossier — public-source company profileTruGreen is the United States' largest lawn care provider, offering tailored lawn, tree, shrub, and pest/mosquito control services to residential customers nationwide. The company employs over 10,000 people and reports annual revenue of approximately $2.9 billion. It operates across the country with a science-based, customer-centered service model.
- Industry
- Lawn Care & Pest Control Services
- Employees
- 10000+
Attack summary
Severity: high — TruGreen has over 10,000 employees and serves millions of residential customers across the US; a confirmed data publication event at this scale likely involves significant volumes of customer PII and employee records, warranting a high severity rating even without explicit enumeration of data types.The incransom group claims to have compromised TruGreen and has published data ('data_published' status), though no specific data size or ransom demand was stated in the post. The nature of the exfiltrated data and whether encryption occurred is not explicitly described in the available post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Employee data
- Business operational data
What the group claims
TruGreen is the nation's leading lawn care provider offering neighborhoods across the country tailored lawn, tree and shrub care along with protection against mosquitoes and other pests. As a company rooted in scientific expertise with a customer-centered approach, TruGreen helps homeowners achieve an outdoor living space that brings them pride. Employees: 10k+ Revenue: $2.9 Billion Industry: Consumer Services Phone Number: (833) 830-2305
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

