RANSOMWARE VICTIM

MAC Construction & Excavating

akira📅 May 7, 2026
8
same group

Attack Intelligence

MAC Construction & Excavating was compromised in a ransomware attack attributed to akira in May 2026. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

akira operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

MAC is a diversified construction company with integrated divisions working closely together toprovide a wide variety of quality construction and excavation services, quality workmanship - produced by quality people. We will upload 30gb of corporate data soon. DB data (Salary / Income 2490386 rows, Physical Address 223606 rows,Online Account 123070 rows, Phone / Fax 111784 rows, Bank / Financial 73100 rows, IP / Device 5923 rows, Password / Secret 1783 rows, Tax ID 1686 rows, Name (Person) 1074 rows, Email 967 rows, Photo / Biometric 137 rows, FR - Contact 100 rows, Property 28 rows, Employment 18 rows, SSN / National ID 8 rows) and a lot of other internal files.

Other Victims — akira (8)

Quick Facts

Attack DateMay 7, 2026
Intel Sourceransomlook

Threat Group

akira
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.