LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Donlar Construction Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Donlar Construction Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 25, 2025
Donlar Construction Listed by akira Ransomware Group

Reported June 25, 2025.

HIGH
Severity
June 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Donlar Construction has been publicly listed by the Akira ransomware group, with internal files reported to have been exfiltrated. The incident came to light on June 25, 2025, and anyone who may have shared data with the company is urged to review their exposure and take appropriate protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who work for or have done business with Donlar Construction may now face practical questions about whether their personal or financial details have been exposed. Public reporting indicates the company has been listed by the akira ransomware group, which claims to have taken internal files. With the number of people affected still unknown and the exact status of any data release unconfirmed, the immediate concern for individuals is the possibility that sensitive records could be misused for fraud, identity theft, or unwanted contact.

The listing was reported on June 25, 2025. Beyond the group's own statements, independent confirmation of the full scope remains limited, so anyone connected to the firm should treat the situation as a credible risk rather than a settled fact.

What happened

Donlar Construction was listed by the akira ransomware group in a claim reported on June 25, 2025. According to the group's statements, the incident involved a ransomware attack in which internal files were exfiltrated. The group has asserted that it is prepared to upload almost 50 GB of corporate documents. Public detail does not confirm whether encryption of systems occurred, whether any ransom demand was paid, or whether the claimed data has actually been released. The number of people affected is unknown, and no independent verification of the volume or completeness of the material has been published.

What is known rests primarily on the listing itself. The group describes the material as corporate documents that include employee personal information, detailed financial data, project data, incident reports, and NDAs. These remain claims until corroborated by the company or other reliable sources. Timing of the intrusion, the initial access method, and any containment steps taken by Donlar Construction have not been disclosed in the available record.

The group behind it: akira

Akira is a ransomware operation that has been active in recent years and is known for double-extortion tactics. In typical campaigns the group encrypts systems while also copying data, then threatens to publish the stolen material on a leak site if a ransom is not paid. Public reporting has associated akira with attacks across multiple sectors, including construction, manufacturing, and professional services. The group often posts victim names and sample descriptions of the data it claims to hold in order to increase pressure.

In this case the listing of Donlar Construction is presented as an unverified claim by the group. No public statements from Donlar Construction confirming the details of the intrusion or the accuracy of the data description have been included in the available facts. Established patterns of akira activity include the use of ransomware payloads that target Windows environments and the publication of file lists or partial samples, but none of those operational specifics have been independently confirmed for this particular incident.

About Donlar Construction

Donlar Construction is described as a full-service construction organization that operates as a general contractor and construction manager serving Minnesota and the Upper Midwest. Firms of this type typically manage project bids, contracts, site operations, payroll, insurance, and client relationships. They routinely hold employee records, subcontractor agreements, financial ledgers, project plans, safety and incident documentation, and non-disclosure agreements.

A breach involving a construction company can be consequential because the sector handles both personal data of workers and commercially sensitive information about ongoing and completed projects. Exposure of such material can affect employees, clients, and partners who rely on the confidentiality of contracts and financial arrangements. Public detail about Donlar Construction's size, client list, or internal security posture is limited beyond the description provided in the reporting.

The information in question

The available facts state that internal files were exfiltrated in a ransomware attack. The akira group claims the material consists of almost 50 GB of corporate documents that include employees' personal information such as dates of birth, addresses, phone numbers, emails, and medical information, along with detailed financial data, project data, incident reports, and NDAs. These categories are presented as the group's assertions rather than independently verified contents.

Exact data types and the number of individuals involved remain unconfirmed. Organizations in the construction sector commonly maintain personnel files, payroll and benefits records, medical or workers'-compensation information, banking details for vendors and employees, project specifications, cost estimates, and contractual documents. Whether any or all of those categories are present in the claimed archive has not been established by sources outside the group's listing. Readers should therefore treat the specific inventory as unconfirmed.

The real-world impact

For individuals whose information may be involved, the primary risks are identity theft, financial fraud, and targeted phishing. Personal details such as dates of birth, addresses, and contact information can be combined with other publicly available data to open accounts or impersonate the person. Medical information, if present, raises additional privacy concerns and potential for discrimination or social-engineering attacks. Financial and project data could enable business-email compromise or competitive harm if misused.

For Donlar Construction the consequences include operational disruption, potential regulatory notification obligations, contractual liabilities to clients and partners, and reputational damage. Even if systems were restored quickly, the claimed exfiltration means the organization must assess whether sensitive commercial or personal records are now outside its control. Because the number of affected people is unknown and the release status is unconfirmed, both the company and individuals face a period of uncertainty rather than a fully quantified loss.

Were you affected?

If you are a current or former employee, contractor, or client of Donlar Construction, monitor financial accounts and credit reports for unexpected activity. Consider placing a fraud alert with the major credit bureaus and be cautious of unsolicited emails or calls that reference the company or request personal details. Change passwords on any accounts that may have used work-related email addresses, and enable multi-factor authentication where available.

Public confirmation of individual exposure is not yet available. Readers can run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Remain alert for official notices from Donlar Construction or regulators, and treat any unsolicited offers of "breach assistance" with skepticism until verified through trusted channels.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDonlar Construction security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Donlar Construction’s full breach history →

More recent breaches

Alliance Roofing Listed by akira Ransomware GroupApril 1, 2026Rafael Construction Listed by akira Ransomware GroupDecember 24, 2025Farwest Fabrication Listed by akira Ransomware GroupDecember 18, 2025Latitude 33 Planning& Engineering Listed by akira Ransomware GroupDecember 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Donlar Construction Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram