On December 13, 2023, Canadian energy services company High Arctic Energy Services appeared on the leak site of the Black Basta ransomware group. The listing states that attackers exfiltrated 345 GB of internal files from the firm, which provides drilling, well completion, and equipment rental services in Papua New Guinea and western Canada. Anyone whose employment, financial, or personal records passed through High Arctic’s systems may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch haes.ca
Get alerted the next time haes.ca files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about haes.ca’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak Listing
The Black Basta leak site entry for haes.ca explicitly lists five categories of stolen data: Human Resources, Finance, Executive and Governance, Administration, and Projects. The disclosure does not quantify the number of affected individuals or name specific documents. It simply states that internal files were taken during a ransomware incident and are now published for anyone to download. The primary source, accessed via the onion link mirrored on ransomware.live, has remained active since the initial posting.
Why This Matters for You and Your Family
If you or a family member ever worked for High Arctic, applied for a job there, or had business dealings with the company, your personal information could be sitting in one of those 345 GB. HR folders routinely contain full names, dates of birth, Social Insurance Numbers, home addresses, direct-deposit banking details, and dependent information. Finance and administration files often hold invoices, contracts, and scanned identification. Once these records leave corporate control, they become permanent currency for identity thieves, loan fraud, and targeted scams. Even if your own records are not among the stolen files, the precedent is clear: energy-sector vendors and contractors are now routine targets.
Doxxing and Identity-Chain Risks
Leaked HR and executive documents rarely stay isolated. A single spreadsheet linking an employee’s work email to their personal phone number can connect to gaming accounts, social-media handles, and family addresses. Attackers then chain these details across dozens of future breaches, building detailed profiles that lead to doxxing, SIM-swapping, or extortion. Children’s names or school information sometimes appear in benefits files, exposing younger family members to long-term risks. Credential leaks of this type frequently cascade into account takeovers on Steam, Roblox, or other platforms where kids use the same email-password combinations their parents once used at work.