Ransomware victim disclosure
← All victimsmjcelco.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedMar 27, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 27, 2024
About the victim
AI dossier — public-source company profileMJ Celco, Inc. is a family-owned precision metal stamping and sheet metal fabrication company founded in 1965. Operating from 255,000 square feet of manufacturing space with locations in Schiller Park, Illinois and Monterrey, Mexico, the company serves customers across appliance, automotive, commercial, electronics, and telecom industries with custom metal stamping, tooling, and assembly services.
- Industry
- Precision Metal Stamping & Fabrication
- Address
- 3900 Wesley Terrace, Schiller Park, IL 60176, USA
- Employees
- 225
- Founded
- 1965
Attack summary
Severity: high — Confirmed exfiltration of significant business data (1.2 TB) including financial records and engineering/technical data, plus employee personal information. Manufacturing company data of this scale poses operational and competitive risk.BlackBasta claims to have exfiltrated approximately 1.2 TB of data from MJ Celco, including engineering drawings and projects, financial records, and employee personal folders.
Data the group says was taken
AI dossier — extracted from the leak post- Engineering drawings and projects
- Financial data
- Employee personal folders
What the group claims
MJ Celco proudly employs 225 talented employees and has 255,000 total square feet of manufacturing space across our locations. To be the best metal stamping and fabricating company, delivering unmatched quality, fair prices, and excellent customer service.SITE: www.mjcelco.com Address : 3900 Wesley Terrace Schiller Park, IL 60176 USA Tel# 847-671-1900ALL DATA SIZE: ~1.2tb 1. Projects, Engineering, Drawings 2. Financial data 3. employees personal folders & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

