Ransomware victim disclosure
← All victimsIntegra Castings
Claimed by Storm · listed 4 days ago
Status timeline
- ListedAug 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Storm
- Status
- Data leaked
- Country
- Canada
- Sector
- Manufacturing
- Listed on leak site
- Aug 14, 2026
About the victim
AI dossier — public-source company profileIntegra Castings is an ISO 9001:2015 certified gray and ductile iron foundry operating as a division of The CTD Group in Winkler, Manitoba, Canada. The company specializes in melting, molding, and core-making with capabilities including high-production No-Bake lines for castings up to 4,500 lbs, serving industries requiring high-quality iron castings for structural and high-tensile applications.
- Industry
- Iron Foundry & Casting
- Address
- 200 Pacific Street, Winkler, MB R6W 0K2, Canada
- Employees
- 51-200
Attack summary
Severity: low — Data has been published but no proof files, screenshots, or data inventory are described in the leak post. No operational impact or specific sensitive data exposure is detailed.The Storm group claims to have compromised Integra Castings and published data. No specific details are provided in the leak post regarding encryption, exfiltration scope, or data categories affected.
What the group claims
Integra Castings is an ISO 9001:2015 certified gray and ductile iron foundry that specializes in melting, molding, and core-making a variety of materials. As a division of The CTD Group, they focus on producing customized solutions for clients while adhering to strict quality assurance guidelines. Their capabilities include high production No-Bake lines for castings weighing up to 4,500 lbs and advanced quality control processes. Integra Castings serves industries requiring high-quality iron castings, including those needing specific material grades for structural and high tensile strength applications. The company headquarters is located in 200 Pacific Street, Winkler, MB R6W 0K2, Canada. 51-200 Employees
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

