Ransomware victim disclosure
← All victimsIDS Group
Claimed by Rhysida · listed 5 days ago
Status timeline
- Listed
May 27, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- US
- Sector
- Engineering & Consulting
- Listed on leak site
- May 27, 2026
- Data size
- 185 GB
- Records
- 710 files
About the victim
AI dossier — public-source company profileIDS Group is an award-winning multi-discipline design, engineering, and management consulting firm based in Southern California. The company provides design, engineering, and management consulting services.
- Industry
- Engineering & Consulting
- Address
- Southern California, US
Attack summary
Severity: medium — Data exfiltration claimed with auction announcement, but no proof files advertised, no specific data types disclosed, and no operational disruption stated. Medium reflects confirmed claim of data theft without detailed evidence of sensitivity or scale.Rhysida claims to have exfiltrated data from IDS Group and is auctioning exclusive access to the stolen data with a 7-day bidding window. No operational encryption is explicitly mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- business data
- consulting records
What the group claims
IDS Group is an award-winning multi-discipline design, engineering, and management consulting firm based in Southern California.
The leak post
captured from the group's siteIDS Group is an award-winning multi-discipline design, engineering, and management consulting firm based in Southern California. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner!
Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
