On December 06, 2024, the ransomware group DragonRansomware added eosspartners.com to its public leak site, claiming that it had exfiltrated internal files from EOSS Partners during a ransomware attack. The listing, first surfaced through the group’s Telegram channel and mirrored on ransomware.live, states that the company specializing in technological solutions for the oil and gas sector was compromised. No specific number of records or exact data types beyond “internal files” is detailed in the disclosure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch eosspartners.com
Get alerted the next time eosspartners.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about eosspartners.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Primary Listing
The DragonRansomware leak site explicitly names EOSS Partners and lists its domain eosspartners.com as the victim. It describes the company’s operations across Argentina, Colombia, Ecuador, the United States, and additional countries, noting its focus on maintenance and technical support services for oil and gas clients. The posting states that data was exfiltrated during a ransomware incident but does not quantify the volume of files taken or provide samples in the initial listing. Public reporting on the group indicates this style of posting typically precedes demands for payment to prevent broader publication.
Why This Matters for You and Your Family
When a vendor that handles technical infrastructure for energy-sector clients is breached, the ripple effects often reach ordinary people whose information ends up in the compromised systems. If you or your family have worked with oil and gas companies, used services tied to their operational partners, or had personal data processed by firms like EOSS Partners, your details may now sit in an attacker-controlled archive. The disclosure indicates internal files were taken; these frequently contain contracts, employee records, vendor lists, or customer contact information that can be repurposed for identity theft or targeted scams. December 06, 2024 marks the moment this exposure became public, giving threat actors a head start while affected individuals remain unaware.
Doxxing and Identity-Chain Risks
Internal files from a technical services provider commonly include email addresses, phone numbers, employee names, and project details that link professional identities to personal ones. Attackers can chain these fragments with data from previous breaches to build full profiles—mapping a work email to a personal account, then to a home address or family member’s details. This is exactly how doxxing campaigns escalate: one leaked spreadsheet becomes the foundation for harassment, phishing, or account takeovers. Credential leaks of this nature also cascade into gaming platforms; children’s accounts tied to reused parental emails become easy targets once the chain is mapped.