Flo Components
bd_cc775185b2276446 · schema v1 · pii pii-v1
Full breach record for Flo Components →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Sarcoma on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Flo Components FLO Components Ltd. is an automatic greasing systems specialist and has been a leading supplier of “Total Lube Solutions” to major manufacturers since 1977. More recently, FLO has teamed up with AFEX to help FLO customers protect their critical heavy equipment with the only Fire Suppression Systems designed specifically for heavy mobile equipment. With offices in Mississauga, ON and Winnipeg, MB, FLO uses application expertise, qualified installation and service technicians, combined with high-quality products to provide effective Equipment Reliability Solutions for all types of vehicle fire suppression, manual lubrication, central automatic lubrication and fluid handling applications. We design, assemble and install the highest quality automated systems, using components from industry leaders such as AFEX, Graco, SKF, Lincoln, Alemite, Trico, Perma, Oil-Rite, Petro-Canada, Lubcon, Super Lube, Anderol and other world-class manufacturers.Geo: Canada - Leak size: 172 GB Archive - Contains: Files
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 4, 2025
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
sarcoma
According to ransomware.live, Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.