On December 9, 2025, engineering firm CPS, Ltd. appeared on the leak site of the sinobi ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack. The company, based in Grand Forks, North Dakota, provides municipal engineering, transportation planning, water resources, solid waste management, surveying, and land planning services to communities, businesses, and government agencies across North Dakota and northwest Minnesota. While the exact number of individuals whose information may have been exposed remains unknown, any current or former clients, employees, vendors, or partners whose personal or professional records were stored in the firm’s systems may now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch CPS
Get alerted the next time CPS files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about CPS’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that sinobi listed CPS on its leak site and claimed to have stolen internal files. The firm was established in 1979 and maintains project documentation that can include names, addresses, contact details, contract information, and technical data tied to municipal and private clients. No confirmed total of affected records has been released, and the precise contents of the leaked files have not been independently verified beyond the group’s own posting. The incident follows the typical ransomware pattern of initial compromise, data exfiltration, and subsequent public shaming when demands are not met.
Why This Matters for You and Your Family
When a local engineering firm like CPS suffers a breach, the impact reaches far beyond the company. Municipal project records, land surveys, permitting documents, and vendor contracts often contain home addresses, phone numbers, email accounts, and family names. If your property, utility account, or community project was handled by CPS, your information may now sit in an attacker’s archive. That data can be sold, traded, or used to launch targeted phishing, identity theft, or harassment campaigns against you or your family members. Even if you never directly hired the firm, shared government contracts or joint ventures can still expose you indirectly.
The Doxxing and Identity-Chain Risks
Stolen internal files frequently link professional details to personal ones. An email address used for work correspondence can be chained to personal accounts, social-media handles, and even children’s gaming profiles. Once attackers map these connections, a single leak can trigger cascading account takeovers. Credential leaks like this one often surface on multiple underground platforms, allowing other criminals to impersonate you, reset passwords on linked services, or publish your family’s information for harassment. Gaming accounts belonging to children are especially vulnerable because parents frequently reuse passwords or security questions that appear in professional files.