branchgroup.com
cactusThis record tracks a ransomware attack claimed by the cactus group against branchgroup.com. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.
Window Zero
EXPOSURE GAPWindow Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.
Attack Summary
<p>Commercial & Residential Construction.<br><br>“Founded in 1963, The Branch Group is a company that owns and operates different companies that specialize in civil construction, residential and commercial building construction, electrical and pipe installation, and more. The company is based in Roanoke, Virginia.”<br><br>Website: <a href="https://www.branchgroup.com/">https://www.branchgroup.com/</a><br><br>Revenue : $333M<br><br>Address: 442 Rutherford Ave NE, Roanoke, Virginia, 24016, United States<br><br>Phone Number: (540) 982-1678<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BRANCHGROUP/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BRANCHGROUP/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BRANCHGROUP/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BRANCHGROUP/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, Corporate confidential data, customer information, financial\payroll documents, Employees\executives personal data, IT department documents, corporate correspondence, etc.</p><p><img src="/uploads/Chris_Tucker_ID_22fbc5dcab.png" alt="Chris Tucker ID.png"><img src="/uploads/Branch_Sovos_NDA_07014a5eac.png" alt="Branch Sovos NDA.png"><img src="/uploads/Lori_Beth_Hoel_ID_5284d4273e.png" alt="Lori Beth Hoel ID.png"><img src="/uploads/Breeden_Heating_Air_LF_TPQ_2022_09_NDA_48b06d9916.png" alt="Breeden Heating Air - LF TPQ 2022.09 NDA.png"><img src="/uploads/Branch_interim_financial_statements_May_2023_c9b4b7e60d.png" alt="Branch interim financial statements May 2023.png"></p>
Leak Screenshots
SAMPLEProof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.