Metaencryptor lists EllisDon on ransomware leak site

Published September 7, 2026

A ransomware monitoring site says Metaencryptor listed EllisDon Corporation on its leak site. This is an attacker claim, not confirmation that files were stolen or encrypted.

Report priority
High
Involves
EllisDon Corporation
Group
Metaencryptor

What is known

  • The listing doesn't explain how access to EllisDon's systems may have been gained.
  • Ransomware.live indexes public claims without inspecting the underlying stolen material, so the listing doesn't independently establish theft or encryption.

What to do

First, review the Ransomware.live listing as an unconfirmed claim, not a breach notice. If you work for EllisDon, ask its security or IT team whether the claim has been validated and whether your account or device is within the investigation. Clients, subcontractors and partners should ask their EllisDon contact or their own privacy team whether their organization's data was involved. A business relationship with EllisDon doesn't by itself show that you're affected.

Check EllisDon's official notices or contact your organization's privacy team for updates. If they confirm that your accounts or data were involved, follow their instructions for those accounts or data.

Reported details

Ransomware.live records Metaencryptor as the group and says it discovered the EllisDon listing on 2026-09-07 at 13:01 UTC. The page also labels 2026-09-07 as an estimated attack date, which isn't independent confirmation of when or whether an intrusion occurred. The listing doesn't explain how access may have been gained, identify affected systems or verify that files were stolen or encrypted.