Ransomware victim disclosure
← All victimsMerritt Woodwork
Claimed by Insomnia · listed 4 hours ago
Status timeline
- ListedJul 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Insomnia
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jul 31, 2026
About the victim
AI dossier — public-source company profileMerritt Woodwork is a high-end interior woodwork and joinery firm specializing in bespoke solutions for luxury properties, superyachts, and estates. Based in Mentor, Ohio, the company works with top designers and craftsmen to deliver custom interior projects globally, with a portfolio spanning superyachts and high-end residential properties.
- Industry
- Custom Woodwork & Interior Joinery
- Address
- 7198 Industrial Park Blvd, Mentor, OH 44060
Attack summary
Severity: medium — Data has been published by the group (disclosed status confirmed), but the leak post excerpt provided contains no enumeration of sensitive data types, proof files, or specific exfiltration claims. The company handles client information and project details for high-net-worth individuals and entities, which carries moderate sensitivity risk.The insomnia group claims to have compromised Merritt Woodwork's systems and exfiltrated data. No specific details on data types or operational disruption are provided in the available leak post excerpt.
What the group claims
Merritt provides strategic interior solutions for global estates and superyachts, from concept to execution. With precision planning and careful craftsmanship, it partners with top designers and craftsmen to deliver unparalleled results for generations.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

