Ransomware victim disclosure
← All victimsHoyle Tanner
listed as hoyletanner.com · Claimed by BrainCipher · listed 6 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Professional Services
- Listed on leak site
- Sep 17, 2026
About the victim
AI dossier — public-source company profileHoyle Tanner is a civil engineering and infrastructure consulting firm founded in 1973, specializing in planning and design services for aviation, bridges, roadways, water systems, and municipal projects. The firm has completed nearly 13,000 projects and serves public agencies, municipalities, and private developers.
- Industry
- Civil Engineering & Infrastructure Consulting
- Founded
- 1973
Attack summary
Severity: high — Confirmed exfiltration of 33,500 files containing sensitive business data: customer database, banking/ACH documents, payroll, tax forms, and infrastructure plans for critical infrastructure projects. Data published with no indication of redaction.BrainCipher claims to have exfiltrated 33,500 files from Hoyle Tanner, including contracts, proposals, customer databases, HR records, tax forms, banking documents, payroll, insurance information, infrastructure plans, and drone photography. The group published the data and set a ransom deadline of September 25, 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Contracts and agreements
- Commercial proposals
- Invoices
- Customer database
- HR records
- W-9 tax forms
- ACH/banking documents
- Payroll records
- Tax documents
- Insurance information
- Account information
- Infrastructure plans and drawings
- Drone aerial photography
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteWe have 33,500 (33.5k) files, the contents of which include: Contracts and agreements; Commercial proposals; Invoices; Customer database; HR ; W-9 tax forms; ACH/banking documents; Payroll; Taxes; Insurance; Account information; Infrastructure plans and drawings; Drone aerial photography; If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: September 25, 2026 at 13:00
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

