Ransomware victim disclosure
← All victimsAlcast
Claimed by Akira · listed 8 days ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Manufacturing
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileAlcast is a leading aluminum casting company specializing in precision casting, sand casting, and die casting. They serve multiple industrial sectors including agriculture, defense, heavy equipment, and marine applications.
- Industry
- Precision Metal Casting & Aluminum Foundry
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at significant scale (170 GB), including government-issued IDs, SSNs, and employee personal data, combined with business-critical information (contracts, customer data). Data already published status confirms disclosure.The Akira group claims to have exfiltrated approximately 170 GB of corporate data, including employee personal files (passports, driver's licenses, SSNs, addresses), projects, customer information, and contracts. The group has announced intention to publish this data.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal identification documents (passports, driver's licenses)
- Social Security Numbers
- Employee home addresses
- Project files
- Customer information
- Contracts and agreements
- Corporate documents
What the group claims
ALCAST is a leading aluminum casting company specializing in precision casting, sand casting, a nd die casting. They provide high-quality aluminum castings for various industries, including a griculture, defense, heavy equipment, and marine. We will upload 170gb corporate data soon. Employee personal files (passport, DLs, SSNs, address es and so on), projects, customers information, contracts and agreements and so on.
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

