Ransomware victim disclosure
← All victimsIRCO (Ipsco Tubulars / Robroy Industries / or International Rectifier — resolving to IRC Industries or IRCO America)
listed as irco.com · Claimed by ALP-001 · listed 2 months ago
Status timeline
- Listed
Mar 21, 2026
- Ransom deadline
Mar 29, 2026
- Data leaked
At a glance
- Group
- ALP-001
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 21, 2026
- Ransom deadline
- Mar 29, 2026
- Data size
- 5.9 TB
- Ransom demanded
- $7.7B
- Estimated revenue
- $7.7B
About the victim
AI dossier — public-source company profileirco.com appears to be the web presence of an industrial manufacturing company operating in the United States. Based on the domain and sector classification, the company is engaged in manufacturing operations with reported revenues of approximately $7.7 billion, suggesting a large-scale industrial enterprise. Specific product lines or service details could not be confirmed from available sources.
- Industry
- Industrial Manufacturing
Attack summary
Severity: high — 5.9 TB of data is confirmed exfiltrated and marked ready for release by the threat actor, indicating large-scale data theft from a multi-billion-dollar industrial manufacturer. While the specific data types are unconfirmed, the volume and disclosed status (data_published) with an imminent deadline elevate severity to high.The group ALP-001 claims to have exfiltrated 5.9 TB of data from the victim, with the full dataset described as ready for publication. The post lists a deadline of 2026-03-29, suggesting a ransom demand is active with threatened full data release.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial records
- Internal business documents
- Operational data
What the group claims
Country: USA Revenue: $7.7 Billion Storage: 5.9 TB Ready: 5.9 TB Deadline: 2026-03-29 17:41:30
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
