Ransomware victim disclosure
← All victimsJJR Engineering & Fabrication
Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 11, 2026
About the victim
AI dossier — public-source company profileJJR Engineering & Fabrication is a U.S.-based small business specializing in turnkey precision manufacturing for aerospace, defense, space, clean technology, and commercial sectors. Founded in 2011, the company produces over 5,000 unique hard metal parts and components including fittings, clevises, rod ends, and molds, using CNC machining, sheet metal fabrication, and mechanical assembly. It holds AS9100D/ISO9001:2015 certification and serves 55+ global customers including firms such as AAR Corporation.
- Industry
- Aerospace, Defense & Precision Manufacturing
- Employees
- 51-200
- Founded
- 2011
Attack summary
Severity: high — JJR Engineering & Fabrication serves the aerospace, defense, and space sectors, manufactures FAA-regulated aircraft parts, and holds a CAGE code indicating defense contracting activity. Data published from such a company likely includes sensitive proprietary manufacturing data, customer lists, and potentially export-controlled or ITAR-relevant technical information, representing significant national security and business risk even without confirmed PII at scale.The Nightspire ransomware group claims to have attacked JJR Engineering & Fabrication and lists the disclosure status as data_published, indicating exfiltration and/or publication of company data. No ransom amount, data size, or detailed description of stolen data was provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Company business data
- Potentially proprietary manufacturing specifications
- Customer records
- Supply chain and procurement data
- Engineering/design files
What the group claims
Data is not available now.
Sources
- Victim sitejjrfabrication.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

