Harris Steel
bd_0bcf94a9e9812609 · schema v1 · pii pii-v1
Full breach record for Harris Steel →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group DragonForce on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Harris Steel Company is a steel slitting and processing manufacturer that has been operating since 1950, focusing on building long-term relationships with customers and suppliers. The company emphasizes the importance of competing in the market and continuously improving its knowledge of products and capabilities. Harris Steel is dedicated to maintaining a reputation for consistent performance aligned with its business philosophies. The company aims to elevate standards through ongoing improvement at both individual and company levels.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 9, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_b386c201f980a1b72025-04-18 · +8dVerified by operator
- Indiana State AGbd_f05fc7689753b4c12025-04-18 · +8dVerified by operator
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Apr 9, last Apr 18 (IN) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dragonforce
According to ransomware.live, DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.