SolarCraft Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The SolarCraft Listed by alphv Ransomware Group (reported September 22, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continued through 2022 to target mid-sized firms whose operations sit at the intersection of customer data, project files, and supply-chain relationships. Listings on extortion sites became a routine pressure tactic, often appearing before victims had issued any public statement. Against that backdrop, SolarCraft, a long-established solar and clean-energy provider in California’s North Bay, was named on a leak site associated with the alphv ransomware operation.
Public reporting on 22 September 2022 stated that the company had been listed by alphv and that internal files had been exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical detail has not been released. The incident matters because organisations of this type routinely hold customer, employee, and project information whose exposure can create lasting practical risk.
Inside the incident
According to the available record, SolarCraft was listed by the alphv ransomware group on or around 22 September 2022. The sole concrete description of the compromise is that internal files were allegedly exfiltrated in a ransomware attack. No public figure has been given for the volume of data taken, the precise date the intrusion began, the initial access method, or whether encryption of systems occurred alongside the theft. The number of individuals whose information may have been involved is listed as unknown. Beyond the group’s claim on its leak site and the brief characterisation of “internal files,” no independent confirmation of the full scope has been published in the materials at hand. In short, the public picture is limited to the listing itself and the statement that exfiltration took place.
The group behind it: alphv
alphv, also widely known in security reporting as BlackCat, emerged as a prominent ransomware-as-a-service operation in late 2021. The group has typically operated a double-extortion model: encrypting victim systems while simultaneously copying data and threatening to publish it unless a ransom is paid. Affiliates have used a range of initial-access techniques common to the broader ransomware ecosystem, after which the operators or their partners deploy the alphv payload and manage negotiations through dedicated leak sites. alphv listings have historically covered organisations across many sectors and geographies; the appearance of a victim name on such a site constitutes a claim by the group rather than independent verification. Nothing in the present record attributes specific additional statements by alphv about SolarCraft beyond the listing and the characterisation of internal-file exfiltration.
SolarCraft and its sector
SolarCraft describes itself as the North Bay’s leading solar provider for more than 35 years, offering solar and clean-energy solutions intended to deliver financial and environmental benefits to clients. The company states that it is 100 percent employee-owned. Firms in the residential and commercial solar sector typically manage customer contracts, site surveys, system designs, financing or rebate documentation, installation schedules, and ongoing service records. They also maintain ordinary business data such as employee records, vendor agreements, and internal financial or operational files. A breach at such an organisation is consequential because the data often links identifiable individuals to physical addresses, energy-usage patterns, and payment arrangements, and because disruption can affect both household customers and commercial project timelines.
What was likely exposed
The facts state only that internal files were exfiltrated. No inventory of specific data types—such as names, contact details, Social Security numbers, financial account information, or engineering drawings—has been publicly itemised. Organisations of SolarCraft’s type commonly hold customer PII and project documentation, employee HR files, and proprietary business records. It is therefore reasonable to expect that some mixture of those categories could have been among the taken files, yet the exact contents remain unconfirmed. Readers should treat any more granular description as speculative until additional authoritative disclosure appears.
Why it matters
For individuals, the principal risks are secondary misuse of personal or financial details that may have been present in customer or employee files—phishing that references real project or account information, identity fraud, or unwanted contact. Because solar installations are tied to physical properties, address and system data can also aid more targeted social-engineering attempts. For the organisation, the consequences include potential regulatory notification duties, contractual obligations to clients and partners, remediation costs, and reputational strain, especially for an employee-owned firm whose local reputation is central to its business. The absence of a published headcount of affected people does not reduce the need for caution; it simply means the scale of individual impact cannot yet be quantified from public sources.
If your data was in this claimed breach
If you have been a SolarCraft customer, employee, or partner, treat the possibility of exposure seriously even while exact contents stay unconfirmed. Monitor financial and credit accounts for unfamiliar activity, and be sceptical of unsolicited messages that reference solar projects, rebates, or account details. Change passwords on related accounts if you reused them elsewhere, and enable multi-factor authentication where available. Consider placing a fraud alert or credit freeze if you believe sensitive identity data may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets, which provides one practical indicator of wider exposure.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Empresas Públicas de Medellín Listed by alphv Ransomware GroupENPPI - HACKED AND MORE THEN 1100 GB DATA LEAKED! Listed by alphv Ransomware GroupBosselman Energy Inc Listed by alphv Ransomware GroupEgyptian Electric Cooperative Association Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the SolarCraft Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.