On July 15, 2025, solar installation company Greeniverse appeared on the leak site of the dragonforce ransomware group. The attackers claim to have exfiltrated internal files during a ransomware incident. While the exact number of people affected remains unknown, anyone who has worked with or purchased from the company — including homeowners, business customers, and employees — may have personal information now at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Greeniverse
Get alerted the next time Greeniverse files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Greeniverse’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. Greeniverse, which designs and installs solar systems for homes and businesses, was listed on the dragonforce leak site on July 15, 2025. No specific details about the volume or exact contents of the stolen data have been publicly confirmed by the company. Public reporting indicates the attackers followed their usual pattern of stealing data before encrypting systems and then demanding payment to prevent publication.
Why This Matters for You and Your Family
When a company that holds your address, phone number, email, payment details, or installation records is breached, that information can quickly spread beyond the original attackers. If you or your family bought solar panels, requested a quote, or worked with Greeniverse in any capacity, your data could already be circulating on underground forums. This exposure increases the chance of identity theft, phishing campaigns tailored to your solar installation, or unwanted contact that feels personal and credible because the scammers already know where you live.
Credential leaks like this one often cascade into account takeovers on other services where you reused the same email and password. For families, the risk extends to children whose information may appear in household records or shared accounts.