On February 8, 2025, engineering firm Geokon appeared on the leak site of the lynx ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Geokon
Get alerted the next time Geokon files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Geokon’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates that Geokon, a New Hampshire-based company that designs and manufactures geotechnical sensors and instrumentation used in civil, mining, and structural engineering projects worldwide, was listed on the lynx leak site. The listing states that internal files were taken. No confirmed victim count or exact volume of data has been publicly detailed. The primary source remains the lynx leak site itself, hosted at lynxblog.net, with the specific entry indexed by ransomware.live.
Available reporting describes the exposed material as internal company files. Geokon has not yet issued a public statement confirming the breach or detailing what specific records were taken. Industry trackers continue to monitor the leak page for any additional samples the group may release.
Why This Matters for You and Your Family
When a company like Geokon suffers a breach, the ripple effects often reach ordinary people. Clients, suppliers, employees, and partners may have personal or financial details stored in those internal files. If your name, address, phone number, email, or payment information appears in project records, vendor lists, or employee directories, that data may now be in the hands of criminals. Once leaked, it does not expire.