EllisDon Corporation Data Breach

Alleged

metaencryptor Ransomware Claim Involving EllisDon Corporation

Published: Sep 7, 2026 MetaEncryptor
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
EllisDon Corporation
Industry
Building Services
Threat Actor
MetaEncryptor
Date of Incident
Sep 7, 2026

Executive Summary

metaencryptor ransomware listed EllisDon Corporation on its dark web portal on September 7, 2026, as identified through SOCRadar’s Dark Web Monitoring. EllisDon is recognized as one of Canada’s largest companies specializing in construction and building services. The potential data exposure is significant, with 11 employee credentials identified across key platforms including Microsoft 365, Okta, Box, an internal SSO, and a privileged job-orchestration platform. The most recent credentials were logged on September 3, 2026, just four days prior to the ransomware group’s listing. In the preceding 60 days, metaencryptor has claimed approximately 10 other victims, primarily in the Healthcare, Manufacturing, and Other sectors, with a notable concentration of victims in the United States, Canada, and Singapore. Recent notable listings from the group targeting Canadian entities or the professional services sector include Woodlore International Inc., Hologic Inc., ST Engineering, and SIFCO Industries INC. The inclusion of EllisDon aligns with metaencryptor’s established pattern of targeting established North American corporations that possess complex operational infrastructure.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed 25 records associated with the domain ellisdon[.]com. These records are categorized as follows: 11 employee credentials linked to corporate identity and SSO infrastructure (Category A), 3 external-user accounts on EllisDon-owned URLs, 8 corporate email addresses compromised on third-party services, and 1 unclassified record. The key endpoints identified were login.microsoftonline[.]com (Microsoft 365 tenant with 3 @ellisdon.com records), ellisdon.okta[.]com (Okta identity provider with 1 @ellisdon.com record), ellisdon.app.box[.]com (Box corporate tenant), rundeck.ellisdon[.]com (job orchestration and automation platform), sso93.ellisdon[.]com (internal SSO endpoint), and myshares.ellisdon[.]com (internal file-share service with 3 @ellisdon.com records). The compromised credentials span a period from August 1 to September 3, 2026. While some records were originally harvested between 2024 and 2025, they resurfaced within the August–September 2026 window. The rundeck.ellisdon[.]com endpoint is considered the highest-risk exposure due to its job-orchestration capabilities, which could facilitate lateral movement and remote command execution across the organization’s infrastructure. The compromise of Okta and the Rundeck platform represent the most critical immediate concerns. Recommended actions include credential rotation across all affected identity and SSO endpoints, a thorough audit of the Rundeck job execution history, and a review of access logs for Box and internal file-share services dating back to August 2026.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.