On January 12, 2024, Florida-based general contracting firm Builcore appeared on the leak site operated by the Alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which holds Florida state certification and works on commercial, institutional, and high-end residential projects. Anyone whose personal or financial information passed through Builcore’s systems in the past several years may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Builcore
Get alerted the next time Builcore files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Builcore’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The Alphv leak page, accessible at the time via the .onion link hosted on ransomware.live, states that internal files were exfiltrated. It does not publish the total number of records affected, nor does it list specific data types such as client names, addresses, Social Security numbers, banking details, or project bids. The disclosure indicates the data was taken during a ransomware intrusion but provides no timeline for when initial access occurred or when exfiltration happened. As is common with these listings, the group posted samples and threatened full publication if demands were not met. The exact volume and sensitivity of the stolen files therefore remain unknown to the public.
Why This Matters for You and Your Family
If you hired Builcore for a home renovation, worked with them on an institutional project, or had your information stored in their vendor or employee records, your details could be in the stolen material. Contractor client lists routinely contain addresses, phone numbers, payment records, and sometimes copies of driver’s licenses or tax forms. For families, this often includes information on children when guardianship or school-related construction projects are involved. Once such data leaves a company’s control, it circulates among criminals who combine it with other breaches to build complete profiles. The breach therefore creates long-term risk of identity theft, loan fraud, and unwanted contact even if you never reuse the same passwords.
The Doxxing and Identity-Chain Implications
Ransomware groups like Alphv rarely stop at posting generic files. They harvest any documents that link email addresses, usernames, phone numbers, and physical addresses. These fragments become the starting points for doxxing chains that can expose family members, reveal children’s online gaming handles, or tie personal accounts to real-world identities. A single leaked contractor invoice can connect your home address to an email address used for your child’s Roblox or Fortnite account. That linkage lets attackers attempt credential-stuffing attacks across gaming platforms, leading to account takeovers, harassment, or further extortion. The identity-chain risk is therefore not limited to financial loss; it can reach every online handle tied to your household.