The US-based CRI Electric ransomware claim attributed to the rhysida threat actor involves theft of employee federal account artifacts, vendor tax documents, payroll and privileged HR/legal correspondence, and corporate financial and certification records. Impacted country(s): #UnitedStates
Incident Details
- Victim: CRI Electric
- Sector: Energy & Utilities
- Country: US
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=264
- Discovered: 2026-08-22T05:56:26.446012+00:00
- Published: 2026-08-22T05:55:56.903592+00:00
Information
- Employee federal account artifacts, including Login.gov personal recovery keys, TSP, ID.me, DoD DS Logon, and PIEE access data.
- Vendor W-9 forms, payroll records, HR-lawyer privileged correspondence, and OSHA-related injury or incident reports with photos.
- Public-sector bid pricing for 2025–2026 projects, including SAWS HQ EV charging, SAISD, and NISD, with bid-competitiveness and Davis-Bacon certified payroll context.
- Corporate documents such as SDVOSB certification, Articles, bylaws, stock ledgers, QuickBooks financials, and a Power of Attorney.
- Additional sensitive business records and related materials.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.