Ransom! John Engel Team (SEP-2026)
ShadowByt3$ ransomware claims to have exfiltrated 14,476 unique customer profiles from John Engel Team in the US, including identity/client databases, detailed behavioral/intent analytics, and corporate invoice and payment data. The actor threatens to leak proof (including an image URL) unless negotiations are completed within 72 hours, offering contact via [email protected] to remove their name and cease the breach. #UnitedStates

Incident Details

  • Victim: John Engel Team
  • Sector: Professional Services
  • Country: US
  • Actor: ShadowByt3$
  • Source: https://transfer.it/t/SnxE0AtDWD4A
  • Discovered: 2026-09-10T05:25:30.437382+00:00
  • Published: 2026-09-10T05:25:07.819230+00:00

Information

  • John Engel Team, US: ShadowByt3$ claims to have breached the company and is demanding negotiation to avoid public release.
  • The attackers say they have serious stolen data and provide an image link as β€œproof” of the compromise.
  • They claim the leak includes 14,476 unique customer records, divided into nurtured, archived, and awaiting nurture contacts.
  • They say they stole detailed behavioral tracking and intent analytics, including scout scores, property views, alert activity, email engagement, and error logs.
  • They claim possession of corporate financial and transaction data, including 40 invoice PDFs and an active corporate Visa card ending in 8265 with an expiration date of 01/29.
  • They also claim direct brand impersonation assets, including leader contact details, real estate license information, cloud-hosted branding files, and onboarding text templates.
  • The provided CSV structure includes fields for contact identity, behavior metrics, alert activity, and engagement history.
  • They threaten to sell the data on underground forums and send proof to public breach-reporting sites if no negotiation occurs.
  • They state a 72-hour deadline, with an alleged leak date of 09/12/2026 at 10:10 PM New York time.
  • A negotiation session ID and a ProtonMail address are given as contact methods.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live