The Robins & Morton Group
bd_585ae7a874b27178 · schema v1 · pii pii-v1
Full breach record for The Robins & Morton Group →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Dunghill on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Robins and Morton is a company operating as a construction firm. It specializes in planning and design, construction management, multiple delivery methods, self-performed work, and green building. The company serves healthcare, government, and commercial markets. In the past ten years alone, it have completed nearly $10 billion in projects. These projects vary from major new hospitals and complex renovations, to hospitality projects and a variety of other commercial work.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 26, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_0a7e0c6f17f6212a2022-12-22 · +278dVerified
- Indiana State AGbd_703882936659a7e72022-12-22 · +278dVerified
- Montana State AGbd_dcfc3935e1b1c6e42022-12-22 · +278dCandidate
- Maine State AGbd_e92c118c936916db2022-12-22 · +278dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Dec 22 (MA), last Sep 26 — a 278-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dunghill
According to ransomware.live, Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large enterprises across healthcare, finance, industrial, and technology sectors using a highly selective non-affiliate model, and responsible for a record-breaking $75 million ransom payment in 2024.