Unipres Alabama Inc.
bd_05b79b6d139b72bf · schema v1 · pii pii-v1
Full breach record for Unipres Alabama Inc. →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group DragonForce on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Unipres is a leading manufacturer of press-formed automotive components in the world. It designs, develops and offers car body structural parts, including upper and lower car body parts, bumper parts, front side members, steering members , fuel tanks and transmission products.It started working in United Kingdom in 1987 and is headquartered in Sunderland. The company is a wholly owned subsidiary of Unipres Corporation
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Dec 18, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_13d31e5a7248e98b2025-12-26 · +7dCandidate
- Indiana State AGbd_4642079814b10acd2025-12-26 · +7dCandidate
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Dec 18, last Dec 26 (IN) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dragonforce
According to ransomware.live, DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.