Erivan Gecom Inc Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Erivan Gecom Inc Listed by rhysida Ransomware Group (reported June 22, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On June 22, 2024, Erivan Gecom Inc was listed by the ransomware group known as rhysida. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details about the incident have not been disclosed.
The listing places the company among victims claimed by a group that routinely publishes data after encryption and theft. For employees, clients, and partners of a civil-engineering firm, the appearance of internal files on a leak site raises concrete questions about what material may now be outside the organisation’s control.
What happened
According to the available record, Erivan Gecom Inc was listed by the rhysida ransomware group on June 22, 2024. The group claims that internal files were exfiltrated during a ransomware attack. No public confirmation of the full scope, the precise date of intrusion, the encryption status of systems, or any ransom demand has been released. The number of individuals whose information may have been involved is listed as unknown. Beyond the claim of internal-file exfiltration, method and scale remain undisclosed.
Inside rhysida
Rhysida is a ransomware operation that became publicly visible in 2023. It functions as a ransomware-as-a-service group, providing tools and infrastructure to affiliates who carry out the actual intrusions. Its typical pattern involves initial access—often through phishing, compromised credentials, or unpatched remote services—followed by lateral movement, data theft, and encryption of systems. The group then posts victims on a dedicated leak site and threatens to release stolen material if payment is not made. Rhysida has previously claimed attacks across healthcare, education, manufacturing, and government-adjacent sectors. Listings on its site constitute claims by the group; they are not independent verification that every asserted detail is accurate. In this case, the public record consists solely of the listing of Erivan Gecom Inc and the statement that internal files were taken.
Who is Erivan Gecom Inc?
Erivan Gecom Inc is a civil-engineering and construction company founded in 1981 by Pierre Lajeunesse. It was initially known simply as Erivan and specialised in large-scale concrete works. Organisations of this type routinely manage project plans, engineering drawings, contracts, supplier records, employee information, and client correspondence. A breach involving internal files therefore carries potential consequences for ongoing construction projects, commercial relationships, and the personal data of staff and partners. Because the firm operates in infrastructure-related work, the integrity of its technical and contractual documents is of practical importance to clients and regulators.
What was likely exposed
The only data type named in the public record is “internal files” said to have been exfiltrated. Exact contents have not been itemised. Companies engaged in civil engineering and large-scale concrete construction typically hold engineering drawings, project schedules, bid documents, financial records, employee personnel files, and client or subcontractor contact details. Whether any of these categories were among the files taken remains unconfirmed. Public detail is limited to the group’s claim of internal-file exfiltration; no inventory, file count, or sample has been independently verified.
Why it matters
For individuals whose information may appear in the stolen material, risks include identity misuse, targeted phishing, or exposure of employment and contact details. For the organisation, release of internal project or commercial documents can affect competitive position, contractual obligations, and trust with clients. Because the number of people affected is unknown and the precise contents remain undisclosed, the full extent of downstream impact cannot yet be measured. The incident also illustrates the continuing pressure ransomware groups place on mid-sized industrial firms whose operational data is valuable both for extortion and for secondary misuse.
If your data was in this claimed breach
If you have a past or present connection to Erivan Gecom Inc—as an employee, contractor, or client—consider the following practical steps:
- Monitor financial and credit accounts for unusual activity and enable available fraud alerts.
- Treat unsolicited emails or calls that reference the company or its projects with caution; verify any request through known official channels.
- Change passwords on accounts that may have shared credentials with work systems, and enable multi-factor authentication where possible.
- Request a free exposure scan of your email address against known breach data sets to determine whether your information has already appeared in public dumps.
Further official statements from the company or law-enforcement agencies, if released, should be followed for updated guidance. At present, the public record remains limited to the June 22, 2024 listing and the claim of internal-file exfiltration.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Delmar International Listed by rhysida Ransomware GroupCoastal Pacific Xpress Listed by rhysida Ransomware GroupT Smiles Dental Listed by rhysida Ransomware GroupPembina Trails School Division Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Erivan Gecom Inc Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.