LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › thompsoncreek.com_wa Listed by blackbasta Ransomware Group

HIGH severityUnverified claimHow we verify

thompsoncreek.com_wa Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 10, 2024
thompsoncreek.com_wa Listed by blackbasta Ransomware Group

Reported June 10, 2024.

HIGH
Severity
June 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The thompsoncreek.com_wa Listed by blackbasta Ransomware Group (reported June 10, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or financial information may sit inside a company’s internal systems have a practical reason to pay attention when a ransomware group claims to have taken those files. On June 10, 2024, the group known as blackbasta listed thompsoncreek.com_wa on its leak site, asserting that it had exfiltrated a large volume of internal data from Thompson Creek Window Company. The number of individuals affected remains unknown, and public detail about the incident is limited to what the group itself has claimed.

For employees, clients, and others whose records may have been among the files, the listing raises concrete questions about exposure of payroll details, tax forms, hiring records, and personal documents. Until the company or independent investigators confirm the scope, those questions cannot be answered with certainty, but the claim alone is enough to warrant careful monitoring of accounts and documents.

Breaking down the breach

According to the public listing dated June 10, 2024, blackbasta claimed responsibility for a ransomware attack against thompsoncreek.com_wa in which internal files were exfiltrated. The group stated that the total volume of data taken was approximately 750 GB and described the contents in broad categories: corporate data; financial data and accounting materials; human-resources and hiring data; payroll records, personal tax forms, and agreements; and personal documents belonging to employees and clients, among other materials. No independent confirmation of the attack method, the exact date of intrusion, or the precise inventory of files has been made public. The number of people whose information may be involved is listed as unknown. Public reporting on the incident rests on the group’s leak-site claim rather than on verified disclosures from the company or law-enforcement sources.

Who is blackbasta?

BlackBasta is a ransomware operation that became publicly active in 2022 and has since been associated with double-extortion attacks: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group typically targets mid-sized and larger organizations across multiple sectors, using common initial-access techniques such as phishing, exploitation of unpatched remote-access services, or compromised credentials. Once inside a network, operators move laterally, exfiltrate selected data, and deploy ransomware. Listings on the group’s leak site are claims of successful intrusion and data theft; they are not independent verification that every asserted file set was in fact taken or that the victim has been fully compromised. BlackBasta has been linked to numerous prior incidents involving corporate, financial, and human-resources data, but those earlier cases do not automatically establish the details of any single new listing.

About thompsoncreek.com_wa

Thompson Creek Window Company, operating as thompsoncreek.com_wa, is a Mid-Atlantic home-improvement firm that has manufactured and installed replacement windows, doors, gutters, siding, and roofing since 1980. Its public address is listed as 4200 Parliament Place, Suite 600, Lanham, Maryland 20706. Companies of this type typically maintain customer project files, contracts, payment records, employee payroll and tax information, supplier agreements, and internal financial and operational documents. A breach claim against such an organization is consequential because the data sets it holds often combine personally identifiable information of both employees and residential clients with financial and contractual records that can be reused for fraud or further social-engineering attacks.

What data was at risk

The only data types named in connection with the incident are those asserted by blackbasta: internal files described as corporate data, financial and accounting materials, human-resources and hiring records, payroll information, personal tax forms, agreements, and personal documents of employees and clients, totaling roughly 750 GB. Exact contents remain unconfirmed by the company or by independent forensic reporting. Organizations in the home-improvement and manufacturing sector commonly store customer contact details, project specifications, payment histories, employee Social Security numbers or tax identifiers, bank-account information used for payroll, and signed contracts. Whether any of those specific items were among the files claimed by the group has not been publicly verified.

What's at stake

For individuals whose information may have been included, the practical risks include identity theft, tax-related fraud, unauthorized use of financial accounts, and targeted phishing that references real employment or project details. Employees could face exposure of payroll and tax forms; clients could face exposure of personal documents tied to home-improvement contracts. For the organization itself, the stakes include potential regulatory notification obligations, contractual liabilities to customers and partners, operational disruption if systems were encrypted, and reputational damage that can affect sales and hiring. Because the number of affected people is unknown and the precise file inventory is unconfirmed, the full scale of these risks cannot yet be quantified.

Were you affected?

If you are a current or former employee, contractor, or customer of Thompson Creek Window Company, treat the blackbasta listing as a reason to review your financial statements, tax filings, and credit reports for unexpected activity. Change passwords on any accounts that may have reused credentials associated with the company, and enable multi-factor authentication where available. Monitor for phishing messages that reference windows, roofing, or employment details. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official confirmation of impact, if any, would come from the company or from regulatory notices; until then, the prudent course is heightened vigilance rather than assumption of either safety or confirmed compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companythompsoncreek.com_wa security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See thompsoncreek.com_wa’s full breach history →

More recent breaches

schuff.com Listed by blackbasta Ransomware GroupNovember 20, 2024gfemlaw.com Listed by blackbasta Ransomware GroupOctober 31, 2024andyfrain.com Listed by blackbasta Ransomware GroupOctober 23, 2024suit-kote.com Listed by blackbasta Ransomware GroupOctober 16, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the thompsoncreek.com_wa Listed by blackbasta Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by blackbasta — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram