Skip to content Dark Web Informer - Cyber Threat Intelligence

📢 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Get foundational access to breach intelligence — track breaches, leaks, and threats in real-time with unfiltered screenshots and expert summaries.

📚
4,000+ Blog Posts: Continuously updated with breach reports and threat summaries.
📢
15,000+ Alerts: Access detailed breach, leak, and DDoS alerts updated daily.
📤
Unredacted Threat Feed: Track breaches and leaks in real-time with JSON export support.
🔍
Leak & Breach Coverage: Get direct access to verified breach posts and claims.
📡
Snippets & Quick Facts: Receive concise summaries of DDoS, defacements, and breaches.
🤖
WhiteIntel.io API Access: Access an integrated API, in breach blog posts.
🖼️
High-Resolution Images: View uncompressed, watermark-free breach evidence.
🔑
Keyword Notifications: Receive browser alerts when monitored keywords are triggered.
📧
Custom Email Alerts: Get curated daily, weekly, or filtered alert summaries.
👥
Telegram Channels: Stay in the know with access to different Telegram channels.
📨
PGP Contact Details: Access verified PGPs for ransomware and threat groups.
⚠️
Coming Soon: CVE Alert Feed – Be first to know when new vulnerabilities emerge.

⚠ Disclaimer
This report includes actual screenshots and/or text that may include unredacted personally identifiable information (PII) gathered from publicly available sources. The sensitive information presented within this report is intended solely for cybersecurity awareness and threat intelligence purposes. Dark Web Informer explicitly condemns unauthorized access, distribution, or misuse of the personal data displayed or referenced here. Users must treat exposed data responsibly and ethically.


📌 Overview
The ransomware group RHYSIDA has listed Cator, Ruma & Associates, a U.S.-based mechanical and industrial engineering firm, as their latest victim. Founded in 1959 and based in Denver, Colorado, the company serves architects and clients across the western and central United States. RHYSIDA claims to have exfiltrated sensitive internal documentation and personal identification records.

A public listing on the group’s Tor-based blog advertises the stolen data at 15 BTC, with a strict “one buyer only” policy and no option for reselling. The group has set a countdown of approximately 7 days before the data is published.


Key Details

AttributeInformation
Date2025-05-28, 01:12:40 PM
Threat ActorRHYSIDA
Victim CountryUnited States
IndustryMechanical or Industrial Engineering
OrganizationCator, Ruma & Associates
Victim Sitecatorruma.com
CategoryRansomware
SeverityMedium
Networktor

Subscriber-only content…

This post is for subscribers on the Pro tier

Subscribe

Already have an account? Sign In

Latest