Ransomware victim disclosure
← All victimsCoe Press Equipment
Claimed by Akira · listed 4 hours ago
Status timeline
- ListedSep 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Sep 22, 2026
About the victim
AI dossier — public-source company profileCoe Press Equipment designs and manufactures coil handling and servo roll feed equipment, including stand-alone roll feeds, precision straighteners, reels, integrated feed systems, and cut-to-length lines for industrial applications.
- Industry
- Machinery & Equipment Manufacturing
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (SSNs, government-issued IDs), combined with sensitive business data (financials, client NDAs) and employee records. No encryption mentioned but data theft severity is critical.The Akira group claims to have exfiltrated approximately 25 GB of corporate data including detailed employee personal information (SSNs, driver's licenses, passports, HR files), financial records, project documents, client documentation, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (SSNs, driver's licenses, passports)
- HR files
- Financial records
- Project documentation
- Client documents
- NDAs and confidential agreements
What the group claims
COE Press Equipment designs and manufactures a complete line of premiere coil handling and serv o roll feed equipment from stand-alone roll feeds, precision straighteners, and reels to comple te integrated feed systems and cut-to-length lines. We will upload 25gb of corporate data soon. Detailed employee personal information (SSNs, drive rs licenses, passports and other HR files), financials, projects, confidential client docs, NDA s and so on.
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

