Reece Noland & McElrath Engineers Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Reece Noland & McElrath Engineers was listed by the sarcoma ransomware group on June 04, 2025, after internal files were exfiltrated. Individuals should check whether their information was exposed and take steps to protect it.
Ransomware groups continue to target professional services firms that hold project files, client records and operational data, using double-extortion tactics that combine encryption with the threat of public leaks. Against that backdrop, a listing that appeared on 4 June 2025 has drawn attention to a mid-sized engineering practice in the United States.
Public reporting states that Reece Noland & McElrath Engineers has been named by the sarcoma ransomware group, which claims to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and independent confirmation of the claim has not been published. The incident matters because engineering consultancies routinely handle sensitive design documents, client contracts and facility information that can be misused if they leave the organisation’s control.
Inside the incident
On 4 June 2025, open-source breach trackers recorded that Reece Noland & McElrath Engineers had been listed by the sarcoma ransomware group. The only concrete detail supplied is that internal files were allegedly exfiltrated in a ransomware attack. No public statement from the firm has confirmed or denied the listing, no timeline of the intrusion has been released, and no figure for the volume of data or number of individuals affected has been disclosed. Method of initial access, duration of presence inside the network, and whether systems were encrypted remain undisclosed.
Who is sarcoma?
Sarcoma is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group posts victim names and sample files on its leak site as pressure. In this case the listing of Reece Noland & McElrath Engineers is a claim made by the group; it has not been independently verified in the available reporting. Sarcoma’s earlier activity has focused on mid-market organisations across multiple sectors, but no further specifics about its alleged interaction with this particular firm have been made public.
About Reece Noland & McElrath Engineers
Reece, Noland & McElrath, Inc. is a client-focused engineering design and consulting firm founded in 1960. It provides feasibility studies, design, construction-phase administration and commissioning services for education, health-care, industrial, commercial and institutional facilities. In addition to traditional HVAC, plumbing and electrical work, the practice has experience with sustainable design elements such as solar systems and rainwater management. Firms of this type typically maintain detailed project drawings, specifications, client correspondence, contracts and internal operational records. A breach at such an organisation can therefore expose both proprietary engineering work and personal or commercial information belonging to clients and staff.
The information in question
The only data category named in public reporting is “internal files” said to have been exfiltrated. Exact contents, file counts and whether any personal data of employees or clients were included remain unconfirmed. Engineering consultancies commonly hold architectural and mechanical drawings, project schedules, cost estimates, email archives, personnel records and client contact details. Until the firm or independent investigators release a verified inventory, any assertion about specific data types beyond the general claim of internal files would be speculative.
Why it matters
If internal project files have left the organisation, competitors or other parties could gain insight into designs, pricing or client relationships. Employees and clients whose contact or contractual information may have been among those files face ordinary risks of phishing, social engineering or identity misuse. For the firm itself, the episode can disrupt ongoing projects, trigger contractual notification duties and require costly forensic and recovery work. Because the scale of the alleged exfiltration is unknown, the precise scope of these risks cannot yet be quantified.
If your data was in this claimed breach
Individuals who have worked with or for Reece Noland & McElrath Engineers may wish to take a few practical steps while waiting for further official detail:
- Monitor financial and email accounts for unexpected activity and enable multi-factor authentication where available.
- Treat unsolicited messages that reference the firm or recent projects with caution; verify any request through a known channel.
- Consider placing a fraud alert with major credit bureaus if personal identifiers may have been involved.
- Run a free exposure scan of your email address against known breach data sets to see whether your information has already appeared elsewhere.
Public information about this incident remains limited; any additional Reported Details should be sought from the firm or from official breach-notification channels once they become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
DMG Contractors Listed by sarcoma Ransomware GroupKaye Lifestyle Homes Listed by sarcoma Ransomware GroupSchultz Industries Inc. Listed by sarcoma Ransomware GroupSöllner Listed by sarcoma Ransomware GroupLatest breaches
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.