Ransomware operators linked to dragonforce allegedly exfiltrated and leaked data from RubberMill, Inc. (rubbermill.com) in the United States, including disk images, credential files, and corporate email archives. The dump also reportedly exposed sensitive PII such as SSNs and payment data, alongside engineering/CAD files and military-spec contract information, impacting #UnitedStates.
Incident Details
- Victim: rubbermill.com
- Sector: Manufacturing
- Country: US
- Actor: dragonforce
- Source: http://xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion/blog/?post_uuid=dabd2c16-5f55-49a2-acd5-28d1de9052f7
- Discovered: 2026-09-06T18:53:26.837039+00:00
- Published: 2026-08-15T22:19:52.015170+00:00
Information
- Large dump containing around 296K files, 276K data objects, and more than 340 GB of data
- Includes a full system image, credential spreadsheets, and password libraries
- Contains corporate email archives, payment records, and insurance documents
- Exposes employee contact lists, personal information records, and tax forms with SSNs
- Holds engineering files such as thousands of CAD drawings, 3D models, and client part references
- Includes sales database data, commercial terms, and customer segmentation information
- Reveals regulatory and compliance materials such as C-TPAT, NAFTA, certificate of origin, and conflict minerals documentation
- Suggests possible military-specification and defense-related contract materials

Disclaimer: This post is based on public claims made by the ransomware group "dragonforce". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.