BaseLeak
580 subscribers
44 photos
95 links
Download Telegram
๐Ÿ” INCIDENT: Hyde Park United Methodist Church (HYDEPARKUMC.ORG)

๐Ÿ“… Date of attackers' claim: February 14, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: hydeparkumc.org

๐Ÿข About the company: Hyde Park United Methodist Church is a religious organization located in the United States (Florida, Tampa). The church was founded in 1888 and is one of the oldest and largest Methodist tradition churches in the region. The organization provides religious services, conducts community programs, and engages in charitable activities. Headquarters is located in Tampa, Florida.

๐Ÿ“ฆ Total leaked archive size: Unknown (data theft confirmed, volume not specified). Only the file list and structure have been published.

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

Potentially leaked data may include:

โ€ข Personal data of parishioners and employees
โ€ข Financial documentation and donations
โ€ข Internal corporate correspondence
โ€ข Charitable program data
โ€ข Volunteer information
โ€ข Contracts with contractors and suppliers

๐Ÿงพ NOTES:

- On February 14, 2026, the CL0P group claimed responsibility for the cyberattack on Hyde Park United Methodist Church
- The attack was discovered on February 14, 2026 (UTC)
- Hyde Park United Methodist Church is one of the oldest churches in Florida, founded in 1888
- No downloadable files are present on the leak page โ€” only the breach claim

โš ๏ธ STATUS:
Leak status: Published (attack confirmed, data leak claimed)
๐Ÿ” INCIDENT: The Mortgage Firm

๐Ÿ“… Date of attackers' claim: February 10, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: themortgagefirm.com

๐Ÿข About the company: The Mortgage Firm is a mortgage lending company based in Orlando, Florida. Founded in 1995, the company operates multiple branches, including several in Brevard County, and has expanded its reach to states such as Alabama, Georgia, Texas, and more. The company offers a range of loan products, including conventional, FHA, VA, USDA, and jumbo loans.

๐Ÿ“ฆ Total leaked archive size: Unknown (data theft confirmed, volume not specified). Only the file list and structure have been published.

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

โ€ข Customer names and addresses
โ€ข Social Security numbers (SSNs)
โ€ข Financial account details
โ€ข Loan documents
โ€ข Information related to mortgage applications
โ€ข Sensitive personally identifiable information (PII)

๐Ÿงพ NOTES:

February 10, 2026 โ€” the CL0P ransomware group announced a cyberattack targeting THEMORTGAGEFIRM.COM, a key player in Canada's financial services industry

The incident was posted on the dark web on February 10, 2026, with the group claiming to have accessed the organization's internal data

The breach has potentially impacted individuals in several states; the total number has not been disclosed

CL0P has amassed 1062 lifetime victims since August 2020

โš ๏ธ STATUS:
Leak status: Published (attack confirmed, data leak claimed)
๐Ÿ” INCIDENT: Dukosi (DUKOSI.COM)

๐Ÿ“… Date of attackers' claim: February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: dukosi.com

๐Ÿข About the company: Dukosi Ltd. is a British technology company founded in 2003 in Edinburgh, Scotland. The company develops revolutionary battery management technologies, including the Chip-on-Cell cell monitoring system and the C-SynQยฎ communication protocol. Dukosi's solutions are used in electric vehicles (EVs), industrial transport, and stationary energy storage systems. The company has offices in the US, Asia, and Europe, with a staff of 100-200 employees. Annual revenue is estimated in the range of 5-25 million, with total funding raised of5โˆ’25million,withtotalfundingraisedof6.4 million.

๐Ÿ“ฆ Total leaked archive size: 1.07 Tb

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

โ€ข R&D and intellectual property in battery management
โ€ข Source code and technical documentation
โ€ข Client and partner information (automakers, battery manufacturers)
โ€ข Employee data
โ€ข Financial documentation
โ€ข Internal corporate correspondence
โ€ข Patent documentation (the company holds 24 patents)

๐Ÿงพ NOTES:

๐Ÿ‘บ In July 2025, Dukosi received ISO 27001 certification, confirming compliance with international information security standards

๐Ÿ˜ˆ The attack was discovered on February 7, 2026 (UTC)

๐Ÿ˜‚ In November 2025, the company received the CLEPA Innovation Award as an SME Top Innovator in the "Green Technologies" category

โšก๏ธ Dukosi is a key player in battery management systems for electric vehicles and energy storage

โš ๏ธ STATUS:
Leak status: Published (attack confirmed, data leak claimed)

๐Ÿ’ซ ๐Ÿ‘ฝ
๐Ÿ” **INCIDENT: Crowded Island (CROWDEDISLAND.COM)

๐Ÿ“… **Date of attackers' claim:
February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ **Compromised domain: crowdedisland.com

๐Ÿข About the company:*
* Crowded Island is an American technology company located in the United States. The exact year of foundation and field of activity are not specified in open sources, however the company is positioned as a leading tech company. According to DNS records, the company uses Microsoft 365 and Proofpoint Essentials for email security, as well as SPF protection against domain spoofing.

๐Ÿ“ฆ **Total leaked archive size: Unknown (data theft confirmed, volume not specified). 7.69 Gb have been released. The file list and structure have been published.

๐Ÿ“‚ **WHAT LEAKED (attackers' statement + data analysis):


โ€ข Technical documentation and source code (as a technology company)
โ€ข Client and partner data
โ€ข Personal data of employees
โ€ข Financial documentation
โ€ข Internal corporate correspondence
โ€ข Cloud infrastructure configurations
โ€ข Data from Microsoft 365 (Proofpoint Essentials MX records discovered)

๐Ÿงพ **NOTES:

- Crowded Island is a technology company, which makes the leak particularly critical due to potential access to intellectual property and client data
- The company's DNS records show the use of SPF (Sender Policy Framework) protection to prevent email spoofing

โš ๏ธ STATUS
:
**Leak status: Published
(attack confirmed, data leak claimed)

๐Ÿ’ซ ๐Ÿ‘บ
๐Ÿ” **INCIDENT: Ideal Welders (IDEALWELDERS.COM)

๐Ÿ“… **Date of attackers' claim:
February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: idealwelders.com

๐Ÿข About the company: Ideal Welders is a Canadian industrial company providing custom metal fabrication services. The company specializes in both complex and simple projects, including the fabrication of precision components and structures. Manufacturing capabilities include pressure vessels, pipe fittings, structural welding, and other services. With over 50 years of experience, the company serves industries such as chemical, pulp and paper, oil, and gas.

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

โ€ข Engineering and technical documentation
โ€ข Drawings and product specifications
โ€ข Client data (chemical, oil and gas, pulp and paper industries)
โ€ข Employee information
โ€ข Financial documentation
โ€ข Contracts and commercial proposals
โ€ข Internal corporate correspondence

โš ๏ธ STATUS:
Leak status: Attack confirmed, data leak claimed)

๐Ÿ’ซ ๐Ÿซฅ
๐Ÿ” **INCIDENT: Strategic Objectives Inc.

๐Ÿ“… Date of attackers' claim: February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: strategicobjectives.com

๐Ÿข About the company: Strategic Objectives Inc. is a Canadian PR agency located in Toronto, Canada. The company provides strategic PR solutions for brand and reputation building, as well as achieving measurable results. The firm serves a wide range of industries, including consumer, lifestyle, retail, and corporate sectors. Services include social and digital communications, crisis management, and event marketing.

๐Ÿ“‚ WHAT LEAKED (attackers' statement):

โ€ข Strategic PR documents and communication plans
โ€ข Client data (consumer, retail, corporate sectors)
โ€ข Employee information
โ€ข Financial documentation
โ€ข Crisis management documentation
โ€ข Internal corporate correspondence
โ€ข Marketing and event campaign data

๐Ÿงพ NOTES:

* The company's DNS records show the use of Microsoft 365 (SPF record: v=spf1 include:spf.protection.outlook.com -all) and Barracuda Networks for email protection
* No downloadable files or visual evidence are present on the leak page โ€” only the breach claim

โš ๏ธ STATUS:
Leak status: Attack confirmed, data leak claimed

๐Ÿ’ซ ๐Ÿซฅ
๐Ÿ” INCIDENT: TRJ Ltd

๐Ÿ“… Date of attackers' claim: February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: trjltd.co.uk

๐Ÿข About the company: TRJ Ltd is a British company providing business services.
๐Ÿ‘บThe exact year of foundation and field of activity are not specified in open sources.

๐Ÿ“ฆ Total leaked archive size: Unknown (data theft confirmed, volume not specified). Only the file list and structure have been published.

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

According to the CL0P ransomware group's statement, the attackers exfiltrated confidential company data. The attackers' statement: "The full leak will be published soon, unless a company representative contacts us via the channels provided."

Potentially leaked data may include:

โ€ข Client and partner data
โ€ข Personal data of employees
โ€ข Financial documentation
โ€ข Internal corporate correspondence
โ€ข Cloud infrastructure configurations
โ€ข Data from Microsoft 365 (MX records for protection.outlook.com discovered)
โ€ข Contracts and commercial proposals

๐Ÿงพ NOTES:

๐Ÿ‘ DNS records of the company show the use of Microsoft 365 (MX record: trjltd-co-uk.mail.protection.outlook.com)
๐Ÿ˜Ž SPF record of the company: v=spf1 include:spf.protection.outlook.com include:spf.UK.exclaimer.net ip4:85.236.147.194/29 ip4:85.236.147.162/29 ~all
๐Ÿ‘ฟ Only the file list and structure have been published.

โš ๏ธ STATUS:
Leak status: Published (attack confirmed, data leak claimed)

๐Ÿ’ซ
๐Ÿ‘บ

๐Ÿ” INCIDENT: VIP Properties LLC

๐Ÿ“… Date of attackers' claim: February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: vippllc.com

๐Ÿข About the company: VIP Properties LLC is an American real estate rental company located in Essex Junction, Vermont. The company was founded in 2011. Field of activity: Real Property Lessors. According to Dun & Bradstreet, the company's annual revenue is approximately $102,573, with 1 employee. Contact person is Jeff Spooner.

๐Ÿ“ฆ Total leaked archive size: Unknown (data theft confirmed, volume not specified). 16.5 Gb have been released. The file list and structure have been published.

๐Ÿ“‚ WHAT LEAKED (attackers' statement + data analysis):

โ€ข Real estate and tenant data
โ€ข Financial documentation and accounting records
โ€ข Personal data of employees and contact information
โ€ข Lease agreements and commercial proposals
โ€ข Internal corporate correspondence
โ€ข Company owner information

๐Ÿงพ NOTES:

- The company's DNS records show the use of Microsoft 365 (MX record: vippllc-com.mail.protection.outlook.com)
- SPF record of the company: v=spf1 include:spf.protection.outlook.com -all
- The company uses a domain registered through GoDaddy (WHOIS email: abuse@godaddy.com)

โš ๏ธ STATUS:
Leak status: Questionable


๐Ÿ’ซ ๐Ÿ˜‚
๐Ÿ‘บ

๐Ÿ” INCIDENT: MNK Associates

๐Ÿ“… Date of attackers' claim: February 7, 2026

๐Ÿฆ  Attackers: CL0P ransomware group

๐ŸŽฏ Compromised domain: mnkassociates.com

๐Ÿข About the company: MNK Associates is a British consulting company registered in Alfreton, Derbyshire, UK (16 Mount Crescent Broadmeadows, South Normanton). The company was founded on April 27, 2016, main activity is management consulting (SIC: 70229). Company status is Active. The CL0P group classifies it as a company in the business services sector.

๐Ÿ“ฆ Total leaked archive size: Unknown (data theft confirmed, volume not specified). The leak page shows the same magnet link as for VIP Properties LLC.

๐Ÿ“‚ WHAT LEAKED (attackers' statement):

โ€ข Client and partner data (management consulting)
โ€ข Personal data of employees
โ€ข Financial documentation
โ€ข Internal corporate correspondence
โ€ข Cloud infrastructure configurations
โ€ข Data from Microsoft 365 (MX records for protection.outlook.com discovered)
โ€ข Contracts and commercial proposals
โ€ข Strategic consulting documents

๐Ÿงพ NOTES:

The company's DNS records show the use of Microsoft 365 (MX record: mnkassociates-com.mail.protection.outlook.com)

SPF record of the company: v=spf1 include:spf.protection.outlook.com -all

Microsoft 365 verification code: MS=ms42271467

The domain is registered through PublicDomainRegistry.com (WHOIS email: abuse-contact@publicdomainregistry.com)

๐Ÿ‘ฟ No downloadable files or visual evidence are present on the leak page โ€” only the breach claim, and the same magnet link as for VIP Properties LLC is indicated

โš ๏ธ STATUS:
Leak status: Questionable

๐Ÿ’ซ ๐Ÿ˜‚
๐Ÿ˜Ž

๐Ÿ” INCIDENT: Brault (BRAULT.US)

* ๐Ÿ“… Date of attackers' claim: February 7, 2026
* ๐Ÿฆ  Attackers: CL0P ransomware group
* ๐ŸŽฏ Compromised domain: brault.us
* ๐Ÿข About the company: Brault is a technology company specializing in document management software development, digital transformation, and workflow automation. Headquarters is located in the USA.

As of February 7, 2026, the company Brault (brault.us) was added to the victim list of the CL0P group. Information about the company and the leak details are based solely on the CL0P group's statements.

### ๐Ÿ“‚ Attackers' statements:

According to the CL0P ransomware group's statement, the attackers exfiltrated confidential company data, including files from servers and cloud storage.

### ๐Ÿงพ NOTES:

๐Ÿ˜‚ On February 7, 2026, the CL0P group added Brault to the victim list on their darknet site.
๐Ÿซฅ Brault develops security and compliance solutions, which makes the incident particularly reputationally sensitive if confirmed.
๐Ÿ‘บ The information is based solely on the attackers' statements and has no confirmation or evidence.

### โš ๏ธ STATUS:

**Leak status: Questionable. Not confirmed.**

--- ๐Ÿ‘น
๐Ÿ‘บ

๐Ÿ” **INCIDENT: INJURYLAWYERS.COM

๐Ÿ“… Date of attackers' claim
: April 28, 2026

๐Ÿฆ  Attackers
: CL0P ransomware group

๐ŸŽฏ Compromised domain
: injurylawyers.com

๐Ÿข About the company
: INJURYLAWYERS.COM is a US-based online platform in the legal services sector that helps injured individuals find qualified attorneys. Operating in the legal referral and marketing industry, the platform helps accident victims find representation for cases involving car accidents, workplace injuries, medical malpractice, and similar claims.

๐Ÿ“ฆ **Total leaked archive size:
Unknown. The first part of the archive, 3.28 Tb + second part - 3.41 Tb.

๐Ÿ“‚ WHAT LEAKED (๐Ÿ˜Ž attackers' statement):

According to the CL0P ransomware group's statement, potentially leaked data may include:

โ€ข Personal client information (name, address, contact details)
โ€ข Injury and medical claim data
โ€ข Financial documentation
โ€ข Internal corporate correspondence
โ€ข Attorney and partner data
โ€ข Cloud infrastructure configurations
โ€ข Data from Microsoft 365 and Salesforce (MX records discovered)

๐Ÿงพ **NOTES:**

- A multi-volume dropbox_backup archive is presented as proof. Files cannot be viewed without downloading all parts. No file list is available.

โš ๏ธ **STATUS:**
**Leak status: Questionable.**

---๐Ÿ’ซ ๐Ÿซฅ