Rees NDT Inspection Services Listed by ElDorado Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Rees NDT Inspection Services was listed by the ElDorado ransomware group on January 22, 2025, following the theft of internal files. Anyone who has shared personal information with the company should review their accounts and consider protective steps.
People who work with or for small industrial-service firms rarely expect their workplace records to surface on a ransomware leak site. When a company that inspects cranes, oilfield lifting gear and related equipment is listed by a threat group, the practical concern is straightforward: internal files may have left the organisation, and those files can contain names, contact details, project information or other material that affects employees, clients and partners.
On 22 January 2025, Rees NDT Inspection Services, a Canadian firm with fewer than 25 employees, was reported as listed by the ElDorado ransomware group. Public detail on the incident remains limited. What is known is that the group claims internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed.
Breaking down the breach
According to the available report, Rees NDT Inspection Services appeared on a listing associated with the ElDorado ransomware group on or around 22 January 2025. The report characterises the event as a ransomware attack in which internal files were allegedly exfiltrated. No further technical detail—such as the initial access method, the duration of unauthorised access, encryption of systems, or any ransom demand—has been made public in the material provided.
The scale of the incident is unknown. No figure has been given for the volume of data taken, the number of systems involved, or the number of individuals whose information may be present in the files. The organisation operates in the energy, utilities and waste sector in Canada, with revenue reported as under $5 million. Beyond the claim of internal-file exfiltration, the exact contents of any stolen material remain undisclosed.
The group behind it: ElDorado
ElDorado is a ransomware operation that has appeared in public reporting as a group that encrypts victim systems and threatens to publish stolen data if payment is not made. Like many contemporary ransomware actors, it is associated with double-extortion tactics: data is copied before or during encryption, and the threat of public release is used as leverage. Groups of this type typically list victims on dedicated leak sites, sometimes with sample files or descriptions of the material they claim to hold.
In this case, the listing of Rees NDT Inspection Services should be treated as a claim by the group rather than independently confirmed disclosure. Public reporting has not established, from the facts available here, that ElDorado published specific files from this organisation or that any particular volume of data was verified by third parties. The group’s broader pattern of activity—targeting organisations across sectors and using leak-site pressure—is well documented in open sources; claims about any single victim still require independent corroboration.
Rees NDT Inspection Services and its sector
Rees NDT Inspection Services is a small Canadian company serving northwestern Canada from locations in Grande Prairie, Bonnyville and Vegreville, with mobile units that can be dispatched across the region. It specialises in the inspection and engineering certification of overhead lifting devices—cranes, pickers, sideboom pipelayers—and oilfield-related lifting equipment. The firm sits in the energy, utilities and waste sector and employs fewer than 25 people, with reported revenue under $5 million.
Organisations of this type routinely handle operational records, inspection reports, certification documentation, client and site details, and internal administrative material. Because their work supports safety-critical equipment in oilfield and industrial settings, the integrity and confidentiality of their records matter both to the company and to the operators who rely on those certifications. A breach involving internal files can therefore affect more than the firm itself: it can touch employees, contractors and client organisations whose information appears in project or compliance paperwork.
What was likely exposed
The only data type named in the available facts is “internal files” said to have been exfiltrated in a ransomware attack. No inventory of those files has been published in the material provided. Exact contents are therefore unconfirmed.
Firms that perform non-destructive testing and lifting-equipment certification typically hold, among other things, inspection and certification records, client and site information, employee and contractor details, and internal operational documents. Whether any of those categories were present in the material claimed by ElDorado has not been established publicly. Readers should treat any assumption about specific personal or commercial data as speculative until more detail is released by the organisation or by independent reporting.
What's at stake
For individuals whose details may appear in internal files, the main risks are misuse of contact or identity information, targeted phishing that references real projects or workplaces, and the longer-term possibility that personal data circulates in secondary markets. For the organisation, the stakes include operational disruption if systems were encrypted, reputational harm with clients who depend on certified inspections, potential regulatory or contractual obligations to notify affected parties, and the cost of investigation and recovery.
Because the number of people affected is unknown and the precise file contents are undisclosed, it is not possible to quantify the exposure. The practical consequence is uncertainty: those connected to the firm cannot yet know whether their information was involved, and the company must manage both the technical aftermath of a claimed ransomware incident and the communication needed with staff and clients.
Were you affected?
If you are an employee, contractor or client of Rees NDT Inspection Services, treat the listing as a reason for caution rather than proof that your data was taken. Practical first steps include:
- Watch for unexpected emails or calls that reference the company, inspections or oilfield work and that ask for credentials, payments or sensitive information.
- Change passwords on work-related and personal accounts if you reuse credentials, and enable multi-factor authentication where available.
- Review financial and account statements for unusual activity if you have shared banking or identity details with the firm.
- Contact the organisation through a known, official channel if you need confirmation about whether your information was involved; do not rely on unsolicited messages claiming to be from the company or from the threat group.
- Consider running a free exposure scan of your email address against known breach datasets to see whether your address has already appeared in other public incidents.
Public information on this incident remains limited. Further clarity will depend on any official statements from Rees NDT Inspection Services and on independent verification of the claims made on the ElDorado listing.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
EVAS Group Listed by blacklock Ransomware GroupD&G Enviro-Group Listed by blacklock Ransomware GroupGC Custom Metal Fabricationsoon Listed by blacklock Ransomware GroupHIDROCARBUROS ARGENTINOS S.A. Listed by blacklock Ransomware GroupLatest breaches
Publicly posted by eldorado — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.