Ransomware victim disclosure
← All victimsThermalex Inc
Claimed by Kairos · listed 4 days ago
Status timeline
- ListedJul 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Kairos
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jul 25, 2026
About the victim
AI dossier — public-source company profileThermalex Inc is an aluminum extrusion manufacturer based in Montgomery, Alabama, specializing in high-efficiency and corrosion-resistant products since 1985. The company serves HVAC, automotive, battery cooling, and industrial sectors, with expertise in microchannel tubes and complex custom extrusions.
- Industry
- Aluminum Extrusion & Manufacturing
- Address
- Montgomery, Alabama, US
- Founded
- 1985
Attack summary
Severity: medium — Data has been published (disclosed_status: data_published) with no public site available to verify proof or scope. The company serves industrial and automotive sectors, suggesting moderate business sensitivity, but no regulated data (PII at scale, medical, financial) is explicitly mentioned.The kairos group claims to have exfiltrated data from Thermalex Inc. The specific nature of exfiltration or encryption is not detailed in the post, but the disclosure indicates data publication.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- manufacturing specifications
- client information
What the group claims
Thermalex specializes in aluminum extrusion solutions, offering high-efficiency and corrosion-resistant products since 1985. Based in Montgomery, Alabama, the company serves various industries including HVAC, automotive, battery cooling, and industrial applications. With advanced manufacturing systems and a commitment to quality, Thermalex is recognized as a global leader in the aluminum extrusion industry. Their expertise includes the fabrication of microchannel tubes and complex extrusions tailored to meet diverse client needs.
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

