# Rhysida claims breach of CRI Electric

Published: 2026-08-22 · Severity: high · Sectors: government-national, defense, manufacturing
Canonical: https://vorant.io/reports/bb53a267-eb2d-5eaa-bfc8-9fedbc3727f1/rhysida-claims-breach-of-cri-electric

> Rhysida ransomware group listed San Antonio electrical contractor CRI Electric as a victim, claiming theft of federal employee credentials, vendor SSNs, and bid data.

Ransomware.live tracking indicates the Rhysida ransomware group has listed CRI Electric, a veteran-owned San Antonio electrical services company, as a victim on its leak site, with an estimated attack date of August 22, 2026. The claimed stolen data is notably sensitive for a small business of this size, allegedly including employee federal account artifacts (Login.gov recovery keys, TSP retirement data, ID.me, DoD DS Logon, and PIEE contract payment system access), 151 vendor W-9 forms containing SSNs/EINs, payroll records, privileged HR-lawyer correspondence, OSHA injury reports with photos, public-sector bid pricing for government entities (SAWS, SAISD, NISD), corporate governance documents, QuickBooks financials, and a Power of Attorney.

The exposure of DoD-adjacent credentials (DS Logon, PIEE) and CUI-adjacent bid data is significant given CRI Electric's apparent status as a small/veteran-owned government contractor (SDVOSB), raising downstream risk for federal systems and other public-sector entities if credentials are reused or if identity documents enable further fraud. No specific initial-access vector, malware sample, or technical IOC was disclosed in this listing; the entry is a leak-site claim rather than a technical intrusion report. Organizations with similar profiles — small contractors holding DoD-linked credentials or PII for federal employees — should treat this as a reminder to audit third-party/vendor access to sensitive federal identity systems and enforce credential rotation and MFA on Login.gov, ID.me, and DS Logon accounts tied to contract relationships.

## Mentioned in this report

- Threat actors: rhysida
- Malware: Rhysida

Source reporting: https://www.ransomware.live/id/Q1JJIEVsZWN0cmljQHJoeXNpZGE=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bb53a267-eb2d-5eaa-bfc8-9fedbc3727f1/rhysida-claims-breach-of-cri-electric.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
