# SpaceBears lists D-MAX Engineering as victim

Published: 2026-09-05 · Severity: elevated
Canonical: https://vorant.io/reports/73092c43-68df-5ec1-b2c0-db11e32bae85/spacebears-lists-d-max-engineering-as-victim

> Ransomware group SpaceBears added San Diego environmental consulting firm D-MAX Engineering to its leak site, claiming theft of personal, financial and client data.

Ransomware.live tracked a new leak-site posting by the SpaceBears ransomware operation naming D-MAX Engineering, Inc., a small San Diego-based environmental consulting firm specializing in storm water compliance services for Southern California municipalities, as a victim. The group claims to have exfiltrated employee and client personal information, financial documents, and communication drawings/plans.

No technical details of the intrusion vector, malware used, or ransom demand were disclosed in the listing. The victim organization is a small business enterprise (SBE) serving governmental agencies in San Diego, Orange, Imperial, and Riverside counties, making it a lower-profile target with limited broader ecosystem impact. DNS records associated with the victim's domain (dmaxinc.com) show standard hosting/privacy-protection infrastructure (Bluehost) rather than attacker-controlled infrastructure, and no cloud/SaaS compromise was identified.

This is a single-victim leak-site listing rather than evidence of a broader campaign or novel technique; defenders in similar small/mid-size professional services and environmental consulting firms serving government clients should note SpaceBears as an active ransomware/extortion actor and ensure standard ransomware defenses (backup integrity, credential hygiene, EDR coverage) are in place.

## Mentioned in this report

- Threat actors: Space Bears
- Malware: SpaceBears

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.ransomware.live/id/RC1NQVggRW5naW5lZXJpbmcsIEluY0BzcGFjZWJlYXJz

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/73092c43-68df-5ec1-b2c0-db11e32bae85/spacebears-lists-d-max-engineering-as-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
