S&F Concrete Contractors
bd_c46679e8f9541860 · schema v1 · pii pii-v1
Full breach record for S&F Concrete Contractors →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Dan0n on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 23, 2024
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitedan0nbd_ccfa99986a69f41d2024-05-23Candidate
Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_153c9395263b70032024-08-07 · +76dVerified
- New Hampshire State AGbd_d2d12b8a3b040f552024-08-07 · +76dVerified
- Maine State AGbd_d53a71eb90ab571e2024-08-07 · +76dVerified by operator
- Massachusetts State AGbd_e29c6100dd7a55cb2024-08-08 · +77dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing May 23, last Aug 8 (MA) — a 77-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dan0n
According to ransomware.live, dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.