Ransomware victim disclosure
← All victimsAtrium Windows & Doors
listed as atrium.com · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 30, 2026
About the victim
AI dossier — public-source company profileAtrium Windows & Doors, founded in 1946, is a U.S.-based manufacturer of vinyl windows and patio doors. The company serves both residential and commercial markets, producing products for new construction and replacement applications. It operates as a product-focused manufacturer offering a range of windows and sliding patio doors sold through professionals and direct channels.
- Industry
- Windows & Doors Manufacturing
- Founded
- 1946
Attack summary
Severity: medium — Data is marked as published, indicating confirmed exfiltration has occurred, but no specific sensitive regulated data categories (e.g., PII at scale, medical, financial) are evidenced from the available post, and no data volume or detailed inventory is disclosed.LockBit 5 claims to have attacked Atrium Windows & Doors, with the disclosure status indicating data has been published. The leak post references the company's history and production scale, suggesting exfiltration of company data, though specific data types and volume were not stated in the available excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Company records
- Business data
What the group claims
Since 1946 Atrium Windows and Doors has produced tens of millions of exceptional products throughout...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

