
A ransomware group calling itself Chaos has listed Universal Plant Services, a Texas-headquartered industrial services provider, on its dark web leak site and issued what it called a "final notice" ahead of a threatened data release.
Universal Plant Services describes itself as North America’s leading specialist in rotating and reciprocating equipment services, working with roughly 700 customer facilities across the country and generating $615 million in annual revenue.
The attackers allege that they extracted a broad set of corporate and personal records, including full financial audits, ADP tax filings, payroll data, bank transactions and cash management reports. They also claim to hold employee Social Security numbers, home addresses, dates of birth and confidential health records, along with subcontracts, nondisclosure agreements, customer files, licensing documentation, internal machinery reports, proprietary procurement data tied to Ethos Energy and Energy Services, quality control protocols and project proposals.
Chaos is using the threat of public exposure as leverage to pressure the company into paying a ransom, a pressure tactic common among ransomware operations. The authenticity of the claimed data has not been independently verified.
Cybernews researchers said that if the claims are accurate, the exposure of Social Security numbers would put affected employees at risk of identity theft and fraud, and could draw regulatory scrutiny toward the company. They added that the broader dataset, if genuine, could expose the company’s financial strategies and operational details, potentially leading to client attrition, diminished competitive standing and an expanded attack surface for future intrusions.
Chaos ransomware emerged in mid-2021 and operates on a ransomware-as-a-service model, in which its builder tool allows low-skill threat actors to generate customized ransomware campaigns without coding knowledge or dedicated infrastructure. Variants built on the Chaos framework have primarily targeted schools, small businesses, local governments and individual users, organizations that tend to have weaker cybersecurity defenses.
In 2025, the group targeted the charity organization Salvation Army. Its methods of distributing malware include phishing campaigns, malicious downloads and pirated software. The ransomware is also capable of functioning as a wiper, a dual-purpose design that has made it attractive for politically motivated or destructive campaigns; since Russia’s invasion of Ukraine, Chaos-based malware has been deployed to wipe Ukrainian systems and inflict significant damage.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543