On February 3, 2026, the Akira ransomware group added Forella Group to its leak site and announced plans to publish 457 GB of the company’s corporate data. The construction consulting firm, which provides project management, cost estimating, and dispute resolution services, may have had its internal files exfiltrated in a ransomware attack. The posted material includes detailed employee personal information such as Social Security numbers, passports, driver’s licenses, health records, credit cards, along with financial documents, NDAs, contracts, and confidential project files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Forella Group
Get alerted the next time Forella Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Forella Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the Akira leak site indicates the data was stolen during a ransomware intrusion. The group stated it will upload the full 457 GB archive containing employee personal records and sensitive business documents. No exact number of affected individuals has been confirmed, but the breadth of information described suggests current and former employees, contractors, and possibly client contacts are impacted. Available reporting describes the exposed categories as SSNs, passports, driver’s licenses, health information, credit cards, financial records, NDAs, contracts, and project-specific confidential data.
Why This Matters for You and Your Family
When a company that handles project finances and dispute resolution loses control of employee and client records, the risk lands directly on the people whose information was stored there. SSNs, driver’s licenses, and credit card details can be used to open accounts, file fraudulent tax returns, or impersonate you for years. Health records add another layer of exposure that can lead to insurance fraud or blackmail. If you or a family member ever worked with Forella Group or had your information shared in one of their projects, this claimed breach could affect your credit, employment background checks, or even medical coverage. The volume of data—457 GB—means the exposure is unlikely to be limited to a single spreadsheet.
The Doxxing and Identity-Chain Risks
Credential leaks and personal documents rarely stay isolated. A single exposed email or phone number from this incident can be combined with gaming usernames, social media handles, or school records to build a complete profile. Public reporting indicates that ransomware operators increasingly sell or publish these bundles, allowing other criminals to launch targeted attacks. For families, the danger extends to children: a parent’s work email linked to a child’s gaming account can give attackers a path to bypass parental controls or impersonate family members online. These identity chains turn one breach into repeated harassment, account takeovers, and doxxing campaigns that can last for months or years.