Ransomware victim disclosure
← All victimsFabcon
listed as The Cherokee Group · Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 20, 2026
About the victim
AI dossier — public-source company profileFabcon manufactures and erects precast concrete wall panels for a wide variety of structures, ranging from small machine shops to large-scale distribution centers and multi-story housing facilities. The company operates in the United States and serves commercial, industrial, and residential construction markets. The Cherokee Group appears to be the parent or affiliated entity under which Fabcon operates.
- Industry
- Precast Concrete Manufacturing & Construction
Attack summary
Severity: high — Confirmed exfiltration is claimed with imminent publication of significant sensitive data including employee PII (passports, driver's licenses), financial records, and proprietary project/NDA documents, representing a broad and serious data exposure even though no regulated medical or government data is explicitly mentioned.Akira claims to have exfiltrated corporate data from Fabcon and has indicated it will publish the data imminently; the threatened disclosure includes employee personal identity documents, financial records, project files, drawings and specifications, and NDAs.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Financial records
- Project files
- Engineering drawings and specifications
- NDAs
What the group claims
Fabcon manufactures and erects precast concrete wall panels for e very type of structure. Projects range from a 10,000 square-foot machine shop to a one-million square foot distribution center, an d from a single-story bakery to a 16-story housing facility. We will upload corporate data soon. Employee personal documents ( passports, DLs and so on), financials, projects, drawings and spe cification, NDAs, etc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

