Ransomware group metaencryptor hits EllisDon Corporation
EllisDon Corporation — a professional services target operating in CA has been listed by the metaencryptor ransomware group on 2026-09-07. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | EllisDon Corporation |
|---|---|
| Threat Group | metaencryptor |
| Summary | EllisDon Corporation is a leading Canadian construction and infrastructure services company. Founded in 1951, the company provides construction management, engineering, project development, and facilities management services across a wide range of sectors, including healthcare, transportation, commercial, industrial, government, and defense infrastructure. EllisDon operates across Canada and internationally. |
| Date of Breach | 2026-09-07 |
| Discovery Date | 2026-09-07 |
| Region | CA |
| Target Domain | www.ellisdon.com |
| Business Sector | Professional Services |
| Severity | MEDIUM |
Claim by metaencryptor
EllisDon Corporation is a leading Canadian construction and infrastructure services company. Founded in 1951, the company provides construction management, engineering, project development, and facilities management services across a wide range of sectors, including healthcare, transportation, commercial, industrial, government, and defense infrastructure. EllisDon operates across Canada and internationally.
Posted by the metaencryptor threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
www.ellisdon.com
Leak post (onion / Tor)
https://metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion/0AFC:bead937c43afb39ae1c4ef93551c5a8e4bd2d2dba46039a1709fbd37ae559ef3/0AFC:5eff5080842967d18c801243d2ee0e972875323cf93e8efa5e1c5d3156323f09
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

