Colrich
bd_46e161ced80d2a9f · schema v1 · pii pii-v1
Full breach record for Colrich →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BlackSuit (formerly Royal) on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
From South Africa to Southern California, the ColRich story is a decades-long journey of growth, continuous reinvention and a culture of caring.Through generations of family ownership, the ColRich brand has evolved, but the company’s foundation remains the same today as in the beginning – build lasting communities through a culture centered around innovation, humility, perseverance, and a commitment to helping others.In 1977, business colleagues and friends Richard Gabriel, Barry Galgut and Colin Seid moved from Johannesburg to San Diego, leaving the unrest of apartheid-era South Africa for a more stable environment to raise their families. The trio quickly formed a San Diego-based partnership to pursue development and investment opportunities in Southern California. The business achieved notable success over more than two decades – largely due to continual reinvention and the team’s ability to leverage the peaks and troughs of the cyclical real estate industry.Gabriel’s sons, Graeme and Danny, took the helm in 2003 to build the next iteration of ColRich, creating a diverse residential platform that leverages a unique homebuilding background, renovation expertise, sophisticated in-house construction and design teams brought together in private capital partnerships. Today, ColRich is recognized as an industry leader for integrating design and value into both for-sale and multifamily rental properties.Total downloaded data - 560gb
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 26, 2023
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blacksuit
According to ransomware.live, According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.