On December 14, 2025, engineering and surveying firm Kier & Wright appeared on the leak site of the qilin ransomware group, which claims to have stolen and is prepared to publish the company’s internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Kier & Wright
Get alerted the next time Kier & Wright files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Kier & Wright’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates that Kier & Wright was listed on the qilin ransomware leak site with an entry dated December 14, 2025. The group states it exfiltrated internal data during a ransomware attack and is using the leak site to pressure the victim. The exact number of files or specific records involved has not been independently verified, and the full scope of exposed information remains unclear from available reporting. No customer or employee names have been publicly released at the time of this writing, but the nature of an engineering firm’s internal files often includes project documents, contracts, emails, and spreadsheets that can contain personal information.
Why This Matters for You and Your Family
When a company that handles land surveys, construction plans, or municipal contracts is breached, the data exposed can include your home address, phone numbers, email addresses, and sometimes family member names if you were a client, vendor, or employee. Internal files frequently contain spreadsheets with contact lists that criminals later sell or weaponize. For ordinary families this means heightened risk of identity theft, phishing campaigns tailored to your real-world projects or purchases, and potential harassment if sensitive personal details surface. Even if you have never heard of Kier & Wright, any organization you do business with could be next, and the credentials or details stolen here can be combined with other breaches to build a complete profile of you.
The Doxxing and Identity-Chain Risks
Ransomware leaks like this one rarely stop at the initial data dump. Criminals often cross-reference stolen internal documents with information from earlier breaches, creating long identity chains that link your work email to personal accounts, social-media handles, and even children’s online profiles. A single exposed spreadsheet can give attackers the seed data needed to locate your family across platforms. This is precisely why credential leaks cascade into account takeovers and doxxing chains, especially for gaming accounts that frequently reuse the same passwords or recovery emails listed in corporate files.