On June 11, 2026, Singapore-based mechanical and electrical engineering firm Donjon Pte Ltd appeared on the leak site of the Deadlock Ransomware Group. The company, which provides services to commercial, industrial, and residential clients and holds registration with the Building and Construction Authority, is claimed to have had internal files exfiltrated during a ransomware incident. While the exact number of people whose information may have been exposed remains unknown, anyone whose personal or business records passed through Donjon’s systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch donjon
Get alerted the next time donjon files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about donjon’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from Reports
Public reporting indicates that Deadlock posted Donjon to its leak site on June 11, 2026. The data consists of internal files exfiltrated after the ransomware group gained access to the company’s network. Donjon Pte Ltd, founded in 2003, is a BCA-registered contractor in Singapore that works across multiple building sectors. No confirmed victim count has been released, and the precise types of records taken have not been publicly detailed beyond the broad description of internal files.
Why This Matters for You and Your Family
When a service provider like Donjon suffers a breach, the information you shared with them — invoices, contracts, addresses, phone numbers, or payment details — can end up in the hands of criminals. That data rarely stays isolated. It can be combined with other leaks to build a profile that puts your household at risk of identity theft, phishing, or physical threats. For families, this often means children’s names, school details, or family addresses become easier for attackers to discover and exploit.
The Doxxing and Identity-Chain Risk
Stolen internal files frequently contain email addresses, employee directories, client contact lists, or project documents that link online handles to real-world identities. Once attackers map these connections, one breach can cascade into account takeovers across email, banking, social media, and gaming platforms. Credential leaks of this nature are especially dangerous for gaming accounts belonging to you or your children, where usernames and passwords are often reused and can quickly lead to doxxing chains that expose home addresses and family relationships.