ShadowByt3$ ransomware claims to have exfiltrated 14,476 unique customer profiles from John Engel Team in the US, including identity/client databases, detailed behavioral/intent analytics, and corporate invoice and payment data. The actor threatens to leak proof (including an image URL) unless negotiations are completed within 72 hours, offering contact via [email protected] to remove their name and cease the breach. #UnitedStates
Incident Details
- Victim: John Engel Team
- Sector: Professional Services
- Country: US
- Actor: ShadowByt3$
- Source: https://transfer.it/t/SnxE0AtDWD4A
- Discovered: 2026-09-10T05:25:30.437382+00:00
- Published: 2026-09-10T05:25:07.819230+00:00
Information
- John Engel Team, US: ShadowByt3$ claims to have breached the company and is demanding negotiation to avoid public release.
- The attackers say they have serious stolen data and provide an image link as βproofβ of the compromise.
- They claim the leak includes 14,476 unique customer records, divided into nurtured, archived, and awaiting nurture contacts.
- They say they stole detailed behavioral tracking and intent analytics, including scout scores, property views, alert activity, email engagement, and error logs.
- They claim possession of corporate financial and transaction data, including 40 invoice PDFs and an active corporate Visa card ending in 8265 with an expiration date of 01/29.
- They also claim direct brand impersonation assets, including leader contact details, real estate license information, cloud-hosted branding files, and onboarding text templates.
- The provided CSV structure includes fields for contact identity, behavior metrics, alert activity, and engagement history.
- They threaten to sell the data on underground forums and send proof to public breach-reporting sites if no negotiation occurs.
- They state a 72-hour deadline, with an alleged leak date of 09/12/2026 at 10:10 PM New York time.
- A negotiation session ID and a ProtonMail address are given as contact methods.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.