Ransomware victim disclosure
← All victimsrubbermill.com
Claimed by Dragonforce · listed 2 hours ago
Status timeline
- ListedSep 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Sep 6, 2026
About the victim
AI dossier — public-source company profileRubberMill, Inc. is a women-owned (WBENC-certified), ISO 9001:2015-registered contract manufacturer of custom rubber, foam, and non-metallic component parts for OEM customers in appliance, HVAC, automotive, transportation, and heavy equipment sectors. Based in Liberty, North Carolina, the company operates multiple locations and serves customers requiring volumes from 1,000 to over 10 million units.
- Industry
- Contract Manufacturing – Non-metallic Components (Rubber, Foam, Sealing)
- Address
- 9897 Old Liberty Road, Liberty, NC 27298, USA
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (employee SSNs, tax forms, insurance data), operational technology (CAD/engineering data for defence and OEM clients), financial records, and probable military specifications. Affects supply chain security and regulatory compliance across multiple regulated sectors.DragonForce claims to have exfiltrated approximately 296,000 files totalling 340+ GB, including full system disk images, corporate credentials, email archives, employee PII with SSNs, financial and sales data, complete engineering drawings and CAD files with client part numbers, and regulatory compliance documents including probable military specifications.
Data the group says was taken
AI dossier — extracted from the leak post- System disk image (146 GB)
- AES-encrypted passwords and credential libraries
- Corporate email archive (Outlook PST, 487 MB)
- Payment card data
- Employee personal information and call lists with SSNs
- Insurance records
- Tax forms
- 3,000+ CAD files with client part numbers
- 3D models and client engineering drawings
- Sales database and financial analysis
- Commercial terms and customer segmentation
- C-TPAT, NAFTA, and Certificate of Origin documentation
- Conflict minerals reporting
- Supplier quality assurance and military specifications
What the group claims
═════════════════ ═════════════════ ═════════════════ RUBBERMILL, INC. DUMP: BREAKDOWN OF AN OEM MANUFACTURER LEAK ═════════════════ ═════════════════ ═════════════════ Target: RubberMill, Inc. (North Carolina, USA) — contract manufacturer of non-metallic components for appliance, HVAC, automotive, and heavy equipment. Certifications: ISO 9001:2015, WOSB, WBENC. Probable defense contracts (Mil-Spec). DUMP SIZE: ~296K files / 276K data objects / 340+ GB ▸ 146 GB disk image (.mrimg) — full copy of the system ▸ AES PASSWORDS.xlsx file + APWDxx libraries — credentials ▸ outlook.pst (487 MB) — corporate email archive ▸ creditcard.xls — payment data ▸ EMPLOYEE CALL LIST + Employee Information Record Form — PII ▸ Insurance data ▸ Tax forms containing SSNs ENGINEERING DATA: ▸ 3,000+ CAD files (.dxf, .stp, .dwg) with client part numbers: 7J314, K2A31, K7K11, V1324, etc. ▸ Complete set of 3D models ▸ Client drawings FINANCIAL DATA: ▸ Sales analysis.mdb (38 MB) — complete sales database ▸ commercial terms ▸ customer segmentation REGULATORY RISKS: ▸ C-TPAT / NAFTA / Certificate of Origin ▸ Conflict Minerals Reporting Template ▸ Supplier Quality Assurance Manual ▸ Probable Mil-Spec specifications The dump contains a full cross-section of the business: from passwords and SSNs to automotive OEM drawings and military specifications. ═════════════════ ═════════════════ ═════════════════
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

