DisclosureLens
GLOBALMalwareTechnologyInformationRansomwareInc RansomRansom DemandedActor NamedMedium

Stark Aerospace

bd_f714e5b84b13d4df · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jan 23, 2025

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Stark Aerospace

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: TechnologyDiscovered: 2025-01-23

Source: Ransomware.live

Post text · scraped from the leak site

At Stark Aerospace, we stand as a beacon of excellence in the realm of defense manufacturing. Founded on the principles of integrity and excellence, Stark Aerospace has become synonymous with technological advancement and operational superiority. Our dedication to quality permeates every aspect of our operations, ensuring that each product bearing the Stark Aerospace name upholds the highest standards of performance and durability. ================================================== We have a full range of design documentation, source codes of software environments developed by you, including firmware of all types UAVs you produce, information on contracts with the Department of Defense and other military contractors, supply chain information, and technology partners, codes and parts numbers of the entire component base, building plans and scientific works used by you to manufacture of its products. Moreover, we know the personal data with copies of the passports of your instructors who fly to hot spots for training and presentations of your product solutions. We also found a lot of interesting information on the programs for the production and launch of reconnaissance satellites functionality, as well as partially took away the documentation of your parent holding IAI. Copies of your websites, significant laboratories (in the form of virtual machines), configuration of information security tools and other things - all this is in our possession and will be sold to interested parties in case of refusal to cooperate. 4 TB of company data are at our disposal.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Jan 23, 2025

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.