On May 10, 2024, the ransomware group FunkSec added isurges.com to its public leak site, giving the company until January 3, 2025 to negotiate payment or face the release of stolen internal files that include network secret credentials.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch isurges.com
Get alerted the next time isurges.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about isurges.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Listing
The primary disclosure on the FunkSec leak site states that internal files were exfiltrated during a ransomware attack on isurges.com. The listing names both isurges.com and an affiliated individual, mr J.A. Street, P.E. of jastreet.com, as victims. It explicitly warns that network secret credentials will be leaked if the deadline passes without negotiation for a decryptor. The disclosure does not quantify how many records or individuals are affected, nor does it list every type of file taken. Public views of the page confirm the extortion timer and the threat to publish the stolen material.
Why This Matters for You and Your Family
When a company that handles engineering, infrastructure, or personal projects suffers a breach like this, the people whose information sits in those internal files face direct risk. Even if you never visited isurges.com, your name, address, phone number, email, or project details may have been stored in the compromised systems. Network secret credentials exposed in the planned leak can give attackers a roadmap to move from one service to another, increasing the chance that your own accounts become the next target. For families this means potential identity theft, unexpected bills, or strangers contacting your children using details pulled from the stolen data.
The Doxxing and Identity-Chain Implications
Credentials and internal files rarely stay isolated. A single leaked email and password pair can unlock linked accounts across dozens of services. Attackers chain these findings together: an engineering firm’s client list becomes a phone number, which becomes a gaming username, which reveals your child’s real name and school. This creates persistent doxxing chains that continue long after the initial leak. Credential leaks of this nature have repeatedly led to account takeovers on personal email, banking portals, and family gaming platforms. The longer the data sits on a ransomware leak site, the more likely it is to be downloaded, reposted, and used in follow-on attacks.