Manufacturing

Industry

Irrigation Product Supplier Suffers Cyberattack

February 11, 2025

Azusa, California-based irrigation product supplier, Rain Bird Corporation, suffered a cyberattack in February and is now informing victims of the attack.
“On or about July 25, 2025, Rain Bird became aware of suspicious activity affecting certain portions of the Rain Bird Web Store,” the company said in a letter to victims. “Rain Bird immediately took steps to secure our environment and launched a comprehensive investigation with the assistance of third-party cybersecurity specialists.”
The investigation subsequently determined there was fraudulent activity potentially associated with payment cards used to perform transactions on the Rain Bird Web Store between February 11, and September 5.

read more

Oracle Vulnerability Leads to Attack on NCH

August 15, 2025

Irving, Texas-based NCH Corporation, a maker of industrial maintenance, water treatment and lubricants, fell victim to a cyberattack via a third-party vendor where personally identifiable information ended up stolen in the hack.
“NCH like multiple other organizations use Oracle’s E-Business Suite (“EBS”) software to help manage their operations,” the company said in a notice to victims. “In August 2025, an unauthorized actor leveraged a previously unknown vulnerability in Oracle EBS to take information from numerous organizations’ Oracle EBS applications. NCH learned it was one of those organizations.”
Upon becoming aware of the incident, NCH immediately implemented its response procedures, took measures to secure its implementation of Oracle EBS, and launched an investigation with the support of third-party cybersecurity professionals. NCH also notified law enforcement and is supporting its investigation.
The evidence showed an unauthorized actor obtained files from the NCH Oracle EBS application in mid-August. NCH reviewed the files and, on November 25, determined one or more of the files contained the names, date of birth, Social Security numbers, and benefits enrollment information.

read more

Acoustic Equipment Maker, JASCO Applied Science, Hit in Cyberattack

July 21, 2025

Silver Spring, Maryland-based acoustic equipment maker, JASCO Applied Sciences suffered a cyberattack in July where personally identifiable information of current or former employees ended up stolen in the hack.
“On July 21, 2025, we discovered that an unauthorized party had gained access to our network and engaged in activity which impacted some of our systems,” the company said in a letter to victims. “We responded immediately and took steps to contain the incident, including temporarily taking systems offline.”
Moreover, at the time of the incident, the company said it had no reason to believe any personal information was a part of the attack. However, on October 20, JASCO became aware some personal information ended up purloined in the hack. The company then conducted a review of the data involved and determined some personal information was included in the data set.

read more

Cool Wind Ventilation Suffers Cyberattack

August 29, 2025

Glendate, New York-based metal ductwork manufacturer, Cool Wind Ventilation Corp. suffered a cyberattack in August where a threat actor was able to make off with personally indentifiable information from victims.
“On or about August 29, 2025, we detected a network security incident, in which an unauthorized third-party accessed our network environment,” the company said in a letter to victims. “We immediately engaged third-party forensic specialists to assist us with securing the network environment and investigating the extent of any unauthorized activity.
Cool Wind Ventilation’s investigation, which it completed on October 17, determined an unauthorized third party acquired certain individual personal information during this attack.

read more

Cyberattack at CA Wood Maker

August 26, 2025

Huntington Park, California-based wood manufacturer GL Veneer suffered a cyberattack in August and is now letting victims know there personally identifiable information ended up stolen in the hack.
“GL Veneer experienced a network disruption that affected our ability to access certain systems,” the company said in a letter to victims. “In response, we promptly initiated an investigation, engaging third-party specialists to assist with understanding the nature and scope of the disruption.”
Meanwhile, as part of its investigation, the company learned certain information within its systems was subject to unauthorized access or acquisition on August 26.
Upon discovery, the company worked to identify and collect the data at risk. Additionally, it then began a thorough review to determine the types of information the attackers stole and to whom it belonged to.

read more

Cyberattack at MN Furnace Make

August 1, 2025

Greenbush, Minnesota-based furnace maker, Central Boiler Companies, Inc. fell victim to a “sophisticated cyberattack” in August and discovered personally identifiable information ended up stolen.
“On August 1, 2025, we discovered we ended up victimized by a sophisticated cyberattack,” the company said in a letter to victims. “Upon discovery, we immediately began working with our IT team and third-party forensic specialists to secure the network, restore our systems to operability, and investigate the full nature and scope of the incident.
Central Boiler also said they reported this incident to federal law enforcement.

read more

Japanese High-performance Automotive Suspension Manufacturer Force to Halt Production in Japan and China

October 31, 2025

TEIN, Inc. suffered a ransomware attack on October 31, 2025. The attack hit the main server, affecting all group companies. Japan HQ factory halted production for one day.
The subsidiary factory in China (TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.) was forced to shut down for one week (from November 3). The company is compensating for the lost time by operating on weekends and expects the final impact to be minimal. Their order/shipping system runs on a separate server and was NOT hit by the incident.

The company has not yet confirmed a data leak, internally or externally.

read more

Australian Personal Protective Equipment (PPE) Maker Reports Cyber Incident

October 14, 2025

Ansell Limited, a Australian maker of personal protective equipment (PPE), disclosed unknown attackers exploited vulnerabilities to access company data. The “majority” of data accessed was “non-sensitive business information”. However “a portion… does contain confidential transactional data or personally identifiable information.” Ansell said it had taken “immediate containment action” when the breach was discovered, and that there had been no impact to its operations.

read more

Aussie Fluid Power Hit by Cyberattack

October 16, 2025

Aussie Fluid Power experienced a security incident involving unauthorized access to its IT systems. “While the investigation is ongoing, at this stage it appears the event may have resulted in certain employee, customer, and supplier information being compromised.”

Ransomware group Anubis claimed responsibility for the attack.

read more

German Machinery Manufacturer’s Systems Offline After Cyberattack

October 20, 2025

Weber GmbH acknowledged a cyberattack on the home page of their website: ‘WEBER GmbH was the target of a cyberattack. Data on our servers was encrypted. As things stand, data has also been leaked and published on the dark web. We are working closely with the State Criminal Police Office and other authorities. The aim is to investigate the incident and restore the systems as quickly as possible. IT security experts are supporting us in this. Personal data has also been affected. We are currently checking which data and groups of people are affected. As soon as we have clarity, we will inform you directly in accordance with the GDPR.”

The RansomHouse group claimed responsibility for breaching WEBER GmbH’s network, encrypting systems, and stealing sensitive data.

read more