On January 31, 2025, Mega Metals, a titanium recycling company based in Arizona, appeared on the leak site of the incransom ransomware group. Internal files were allegedly exfiltrated during a ransomware attack, exposing employee contact details including phone numbers and email addresses such as jnathan@megamtls.com and jbuckmaster@megamtls.com. Anyone whose information was stored in those files now faces the risk that their data will be sold or published.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch megamtls.com
Get alerted the next time megamtls.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about megamtls.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from Reports
Public reporting indicates that incransom added Mega Metals to its leak site on January 31, 2025. The posting shows that the attackers successfully exfiltrated internal files before encrypting systems or demanding payment. Available details list specific executives and their direct phone lines, including President Jim Nathan at (602) 258-2000 and additional numbers tied to him and Joe Buckmaster. The exact volume of records taken remains unknown, but the presence of named individuals and contact information confirms that business correspondence and staff details were compromised.
Why This Matters for You and Your Family
When a company you have done business with loses control of its internal files, your personal information can end up in the hands of criminals. Even if you are not an executive, supplier records, customer invoices, or vendor lists often contain home addresses, phone numbers, or email addresses that belong to ordinary families. Once that data reaches a ransomware leak site, it can be downloaded by anyone and combined with other stolen records. The result is a higher chance of identity theft, phishing calls, or unwanted exposure that affects your household, not just the company named in the breach.
The Doxxing and Identity-Chain Risks
Credential leaks and contact details rarely stay isolated. Attackers frequently link an exposed work email to personal accounts, then use those connections to locate social-media profiles, family member names, and even children’s gaming usernames. This creates an identity chain that can lead to doxxing, account takeovers, or targeted harassment. Because many people reuse passwords across work and personal services, a single breach like this one can cascade into compromises far beyond the original victim company. Gaming accounts belonging to your children are especially vulnerable once an associated email or phone number surfaces in these datasets.