DistributionNOW (DNOW Inc.), US, reports a Falcon ransomware intrusion in which attackers exfiltrated 344 GB of corporate and operational data, including bank statements, vendor payment instructions, payroll and tax records, employee PII, SCADA/PLC backups, and internal audit and whistleblower documentation. The organization states the theft spans energy and industrial distribution assets, potentially affecting industrial operations and sensitive governance records in #UnitedStates
Incident Details
- Victim: DistributionNOW (DNOW Inc.)
- Sector: Manufacturing
- Country: US
- Actor: Falcon
- Source: http://i7loab6thvz4lb7jdr3qoeumbvilwhbgnwsctnlfmvsv7g5s3vsiw6yd.onion/#distribution_now
- Discovered: 2026-08-30T14:29:18.522555+00:00
- Published: 2026-08-30T00:00:00+00:00
Information
- 344 GB of extracted corporate data includes bank statements, vendor payment instructions, detailed payroll records, employee compensation, tax documents, operational secrets, and proprietary SCADA gateway backups.
- Also includes PLC logic programs, industrial automation project files, and internal audit logs related to unethical activity investigations.
- Contains whistleblower reports regarding harassment and discrimination, employee disciplinary records, employee PII, passports, driving licenses, medical drug screen results, and more.

Disclaimer: This post is based on public claims made by the ransomware group "Falcon". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.