SpaceBears lists D-MAX Engineering as victim
Ransomware group SpaceBears added San Diego environmental consulting firm D-MAX Engineering to its leak site, claiming theft of personal, financial and client data.
Ransomware.live tracked a new leak-site posting by the SpaceBears ransomware operation naming D-MAX Engineering, Inc., a small San Diego-based environmental consulting firm specializing in storm water compliance services for Southern California municipalities, as a victim. The group claims to have exfiltrated employee and client personal information, financial documents, and communication drawings/plans.
No technical details of the intrusion vector, malware used, or ransom demand were disclosed in the listing. The victim organization is a small business enterprise (SBE) serving governmental agencies in San Diego, Orange, Imperial, and Riverside counties, making it a lower-profile target with limited broader ecosystem impact. DNS records associated with the victim's domain (dmaxinc.com) show standard hosting/privacy-protection infrastructure (Bluehost) rather than attacker-controlled infrastructure, and no cloud/SaaS compromise was identified.
This is a single-victim leak-site listing rather than evidence of a broader campaign or novel technique; defenders in similar small/mid-size professional services and environmental consulting firms serving government clients should note SpaceBears as an active ransomware/extortion actor and ensure standard ransomware defenses (backup integrity, credential hygiene, EDR coverage) are in place.
Mentioned in this report
Detection guidance
1 detection artefacts for this report are available to subscribers.
Source reporting: https://www.ransomware.live/id/RC1NQVggRW5naW5lZXJpbmcsIEluY0BzcGFjZWJlYXJz
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free