Power Grid

CRI Electric — Rhysida ransomware leak-site claim

Leak-site claim surfaced 22 August 2026

Anaheim, California, United States (corporate marker)

33.8400, -117.8700

Loading free detailed map…

What happened

The Rhysida ransomware group listed CRI Electric as a victim on its criminal leak site. Secondary reporting described data theft and encryption, but did not publish victim-supplied confirmation, forensic evidence, affected-data detail or a verified incident date. CRI Electric is an Anaheim-based commercial and industrial electrical contractor rather than a grid operator. No evidence reviewed linked the claim to a power plant, utility control system or customer-site outage, so this is an unconfirmed corporate IT claim represented by a headquarters marker.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Unconfirmed
Confidence
Unverified
Infrastructure
Power Grid
Current temperature
Loading…
Latitude
33.8400°
Longitude
-117.8700°

Attribution

Claimed by Rhysida ransomware group

Public evidence was limited to a criminal leak-site listing relayed by ransomware monitors; CRI Electric had not publicly confirmed a breach.

Sources

  1. Rhysida and SpaceBears Hit CRI Electric and Freelom with RansomwareOvercentral, citing threat-intelligence monitoring · Incident reporting
  2. CRI Electric offers installation and inspections at commercial jobsitesCRI Electric · Official company location and business context only; not confirmation of the ransomware claim