← Back

Dark Project concentrates its first reported victims in North America and shows early pressure on industry, healthcare, and operational services

Leer en Español
Print Share

Executive summary

Dark Project appears as an emerging ransomware threat with an initial public concentration of victims in North America. Based on the set of organizations listed so far, the initial pattern shows 19 victims distributed across three countries: the United States, Canada, and Mexico.

The geographic weight is clear. The United States accounts for 17 of the 19 observed organizations, equivalent to 89.5% of the total. Canada and Mexico each register one victim, with 5.3% respectively. For now, the activity does not show global dispersion. It shows an initial concentrated regional footprint oriented toward North American organizations.

In terms of sectors, the largest block corresponds to manufacturing, industrial equipment, auto parts, packaging, displays, machinery, and transport refrigeration. This group concentrates 6 victims, equivalent to 31.6% of the total. Healthcare and life sciences follow, with 4 victims and 21.1%. Transportation and logistics account for 2 victims, as do construction, engineering, and electrical services, with 10.5% each. The remaining victims are distributed across staffing/professional services, automotive retail, recycling, venue operations, and education.

The relevant detail lies in the type of organizations affected: companies with physical operations, personal data, employee information, technical documentation, financial records, medical data, transportation services, facilities, suppliers, and operational continuity. Dark Project appears to be beginning its public exposure with organizations where extortion pressure can rely on stolen data as well as disruption, regulatory sensitivity, or operational impact.

Key judgments

  • Dark Project shows an initial public concentration in North America: 19 observed victims, with 17 in the United States, 1 in Canada, and 1 in Mexico.
  • The United States accounts for 89.5% of the victims in the analyzed set.
  • Manufacturing and industry represent the most relevant sectoral block, with 31.6% of the total.
  • Healthcare and life sciences represent the second-largest block, with 21.1%, adding regulatory and care-continuity sensitivity.

Geographic distribution

The observed set is fully concentrated in North America.

The United States accounts for 17 organizations: Reid Electric Service, TSC Logistics, Long-Lewis Automotive Group, The Miller Group, Leviton, Mayco International, Sutherland Packaging, The Family Medicine Clinic, Rocky Mount Recyclers, Storer Transportation and Storer Coachways, The Metropolitan Entertainment & Convention Authority, Genesis Engineering Group, Labpharma, Laurel Institutes, Ohio Living Home Health & Hospice, Mile Bluff Medical Center, and Thermo King.

Canada appears with Brainhunter Companies LLC. and Brainhunter Systems Ltd., an organization with Canadian and U.S. operations. Mexico appears with Ruhrpumpen, a global industrial machinery and pump manufacturer headquartered in Nuevo León.

The pattern suggests an initial selection centered on North American organizations of medium size or high operational value, many of them linked to industry, physical services, healthcare, transportation, or commercial infrastructure.

Sectoral distribution

The largest group corresponds to manufacturing and industry: The Miller Group, Leviton, Mayco International, Sutherland Packaging, Ruhrpumpen, and Thermo King. They represent 31.6% of the set. This block includes manufacturers of electrical equipment, auto parts, packaging, displays, industrial pumps, and transport refrigeration. The presence of technical schematics, proprietary documentation, financial information, and employee data can increase the extortion value of this group.

Healthcare and life sciences concentrate 4 victims: The Family Medicine Clinic, Labpharma, Ohio Living Home Health & Hospice, and Mile Bluff Medical Center. They represent 21.1%. This block is especially sensitive because it combines personal, medical, insurance, operational, and care-continuity data. Pressure against healthcare does not depend only on file publication; it also depends on reputational, regulatory, and operational impact.

Transportation and logistics account for 2 victims: TSC Logistics and Storer Transportation and Storer Coachways. They represent 10.5%. This sector can be attractive because of its dependence on operational continuity and movement documentation.

Construction, engineering, and electrical services also account for 2 victims: Reid Electric Service and Genesis Engineering Group. They represent another 10.5%. In this block, the value is not limited to corporate data. The exposure of plans, client documentation, projects, designs, or technical information can generate additional pressure on third parties.

The remaining sectors appear with one victim each: staffing and professional services, automotive retail, recycling and waste management, entertainment/convention venue operations, and technical education. Although each represents 5.3%, the diversity shows that Dark Project does not appear limited to a single vertical.

What pattern emerges

The initial pattern combines geographic concentration and operational diversity.

For now, there is no observed globally dispersed campaign. What appears is an initial public exposure concentrated in North America, with U.S. predominance and marginal presence in Canada and Mexico. There is also no exclusive focus on a single industry. What repeats is another element: organizations that store useful data, depend on operational continuity, and may face pressure over sensitive information related to employees, clients, patients, projects, finances, or technical documentation.

This makes the presence of victims such as Mayco International relevant, where the publication attributed to the actor describes at least 2 TB of data, including internal documents, technical schematics, employees’ personal information, and financial records. Reid Electric Service also appears, where the publication attributed to Dark Project describes approximately 50 GB, including employees’ personal data and clients’ architectural or engineering plans.

In that sense, Dark Project appears to be using a classic extortion logic by selecting organizations where stolen data can have value in itself while also creating indirect pressure on clients, patients, employees, suppliers, or regulatory authorities.

Significance for intelligence

Dark Project is treated as an emerging threat. The initial number of listed victims does not prove technical maturity or operational continuity. But it does provide an early signal affecting an active public surface, a list of North American victims, and a set of sectors where extortion pressure can escalate quickly.

The concentration in manufacturing, healthcare, transportation, engineering, and operational services suggests interest in organizations where internal files are not merely administrative. They may include plans, technical documentation, medical data, employee information, financial records, contracts, routes, operations, suppliers, and material sensitive to third parties.

For threat intelligence, traceability is not limited to monitoring whether more victims appear. It is also highly relevant to observe whether the pattern focused on North America continues.

Analytical closing

Dark Project appears with an initial footprint that is concentrated, not dispersed. North America is the observed terrain. The United States is the center of gravity. Manufacturing, healthcare, transportation, engineering, and operational services form the first surface of pressure.

There is still not enough public material to define the group’s maturity, affiliations, tooling, or continuity. But the initial list already allows an intention to be read.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved