On December 22, 2023, Israeli engineering firm erco.co.il appeared on the leak site operated by the toufan ransomware group. The listing states that the attackers exfiltrated internal files during a ransomware incident and are now publishing samples as part of their extortion campaign. Anyone whose personal or employment data resides in those files is now at risk of identity exposure.
Watch erco.co.il
Get alerted the next time erco.co.il files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about erco.co.il’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The toufan leak site entry for erco.co.il indicates that the company suffered a ransomware attack in which internal data was stolen. The disclosure does not specify the volume of records taken, the exact types of documents involved, or the ransom amount demanded. It simply states that samples of the allegedly stolen material have been uploaded and that further publication will follow if the company does not meet the group’s demands. The listing carries a publication timestamp of December 22, 2023, and remains active on the ransomware.live mirror at the time of writing.
Why This Matters for You and Your Family
When a company like erco.co.il loses control of internal files, the information inside often includes employee names, home addresses, national ID numbers, salary details, tax records, and contact information for suppliers or clients. Any of these records can be used to open accounts, file fraudulent tax returns, or impersonate you. If you or a family member worked at or did business with the firm, your data may now sit in a publicly accessible extortion archive. The breach also raises the possibility that correspondence, contracts, or scanned identity documents were taken, creating long-term risks that extend beyond the immediate victims.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at posting generic samples. Once initial data appears, opportunistic criminals scrape it for email addresses, usernames, and phone numbers that can be cross-referenced with other breaches. These linkages create doxxing chains: an exposed work email leads to a reused password, which leads to a compromised personal account, which eventually reveals family members’ names and locations. Children’s gaming accounts are particularly vulnerable because the same email or password parents use at work is often reused for Roblox, Fortnite, or Steam logins. A single leak can therefore cascade into account takeovers that expose chat logs, friend lists, and even home addresses shared in private messages.