Manufacturing

Industry

Janome America Suffers Cyberattack

October 8, 2025

Janome America, Inc, the Mahwah, New Jersey-based subsidiary of sewing machine manufacturer Janome Sewing Machine Company of Tokyo, Japan, suffered a cyberattack last October and is now letting victims know about the hack.
“On October 8, 2025, Janome discovered that it had experienced a network disruption and immediately initiated an investigation of the matter, the company said in a notice to victims. “Janome engaged independent cybersecurity experts to assist with the process.’
As a result of the investigation, Janome and affiliated companies determined that certain files ended up accessed or stolen.

read more

Heavy Equipment Maker, Etnyre International Suffers Cyberattack

February 19, 2026

Oregon, Illinois-based heavy equipment maker, Etnyre International, suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“On or about February 19, 2026, Etnyre learned of suspicious activity in its computer environment,” the company said in a notice to victims. “Upon discovery, Etnyre promptly launched an investigation to determine the nature and scope of the activity.”
The investigation, which the company conducted with the assistance of third-party forensic specialists, determined an unauthorized threat actor gained limited access to data on Etnyre’s systems between February 19 and February 20.

read more

Cyberattack at Smith-Midland

January 9, 2025

Midland, Virginia-based precast concrete maker, Smith-Midland Corporation (SMC) suffered a cyberattack in January last year and is now informing victims of their personally identifiable information ended up stolen in the hack.
“On or around January 15, 2025, SMC became aware of suspicious activity within their network environment,” the company said in a notice to victims. “SMC launched an investigation and determined that between January 9, 2025 and January 15, 2025, an unauthorized actor accessed certain systems within the environment and copied certain files from those systems.”
SMC conducted a review of the copied files. There were then able to confirm the information stolen, and to whom it belonged to for purposes of providing notice.

read more

Skin Care Manufacturer, Malin + Goetz, Hit in Cyberattack

May 22, 2026

New York, New York-based personal care product manufacturer Malin + Goetz suffered a cyberattack in May where personally identifiable information ended up stolen in the hack.
“On June 15, 2026, we received confirmation from a third-party service provider relating to a potential compromise on our website which we were investigating,” the company said in a notice to victims. “The investigation into the activity identified unauthorized code on our site that may have captured certain information entered on the checkout/payment page, at times between May 22, 2026 and June 10, 2026.”
As a result of the investigation, the company took immediate action to analyze the transactions identified as at risk and determine which customers’ information the threat actor could have taken. Once the company determined that, they would notify them.

read more

TX Conduit Maker, Cantex, Hit in Attack

August 21, 2026

Fort Worth, Texas-based Cantex, Inc., a maker of nonmetallic electrical conduit, suffered a cyberattack where personally identifiable information ended up stolen in the hack.
The breach ended up reported to the Texas Attorney General on Aug. 21, with 1,568 Texas residents identified as affected. Because Cantex’s headquarters is in Texas and this figure represents only the state-mandated Texas-resident count, the true nationwide scope of the incident could be higher if the exposed systems also stored information belonging to employees, vendors, or customers located outside the state.
Stolen in the hack were individuals’ names, home addresses, Social Security numbers, financial account information, and health insurance information. Not only were customers hit in the attack, so too were employees.

read more

Cyberattack at Toy Maker Hasbro

March 28, 2026

Multinational toy manufacturing and media company, Hasbro, Inc. suffered a cyberattack where personally identifiable information ended up stolen in the hack.
Pawtucket, RI-based Hasbro said it implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards designed to help prevent a similar incident from occurring in the future. The company disclosed attackers accessed the personal and financial information of an undisclosed number of employees.
Information stolen in the attack involved name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information, credit or debit card, social security and driver’s license numbers.
Hasbro told Massachusetts regulators the attack traced back to vishing and social engineering, the practice of tricking an employee or help-desk worker into handing over access rather than breaking through a technical defense.

read more

Spectrum Laboratory Products Suffers Cyberattack

August 26, 2026

New Brunswick, New Jersey-based supplier of laboratory equipment and supplies, Spectrum Laboratory Products, Inc., suffered a cyberattack where personally identifiable information ended up stolen in the hack.
In August, the company began notifying individuals their personal information may have been affected by a data security incident.
According to a notification letter filed with the Massachusetts Attorney General’s office and dated August 26, Spectrum Laboratory Products, informed affected individuals of the data security incident affecting their personal information. The letter does not specify the cause of the incident, when the company discovered it , or the type of the data involved.

read more

Cyberattack at Heat Containment Materials Maker, HarbisonWalker International

September 22, 2026

Pittsburgh, Pennsylvania-based refractory products maker, HarbisonWalker International (HWI), suffered a cyberattack where personally identifiable information ended up stolen in the hack.
Forensic disclosures confirmed on September 22–23, 2026, reveal an extortion-driven threat syndicate infiltrated HWI’s corporate enterprise network, traversed IT/OT boundaries, and exfiltrated over 450 gigabytes of sensitive corporate data, according to a report with Sh3llc0d3, an advanced offensive security research lab, threat intelligence platform, and cybersecurity blog focused on ethical hacking, vulnerability analysis, and APT (Advanced Persistent Threat) tracking.
Beyond proprietary refractory material formulas and industrial manufacturing schedules, the actors accessed and extracted executive treasury files, corporate banking ledgers, and wire transfer authorization manifests before deploying secondary extortion demands.

read more

Brazilian Adhesive Product Maker, Engefitas Hit in Ransomware Attack

September 2, 2026

Brazilian manufacturer specializing in adhesive tapes and adhesive products, Engefitas, suffered a ransomware attack by the Vexy Ransomware group which reported the incident on their dark web site earlier this month.
Engefitas makes the specialized adhesive products for the packaging, automotive, construction, electronics, and manufacturing sectors,.
The Vexy Ransomware group is a new group, according to a report with SOCRadar’s Dark Web Monitoring service. It appears Engefitas as one of the initial victims of this new attack group. Vexy Ransomware claims to have stolen internal data when the group released some information September 3..

read more

Scientific Equipment Maker, Kurt J. Lesker Company Suffers Cyberattack

November 12, 2025

Jefferson Hills, Pennsylvania-based scientific equipment maker, Kurt J. Lesker Company (KJLC ), suffered a cyberattack last November and is now informing victims their personally identifiable information ended up stolen in the hack.
“On or about August 4, 2026, KJLC confirmed that certain personal information may have been accessed or taken from KJLC systems between November 12, 2025, to November 13, 2025”, the company said in a notice to victims. “As part of its response to this activity, KJLC took steps to secure its systems and investigate this matter with the assistance of third-party investigators.”
The information that could have been subject to unauthorized access includes name and Social Security number.

read more