A ransomware group operating under the name Storm has posted a claim stating it targeted American Casting Company, with the listing dated September 18, 2026. This information comes from the group’s own extortion site, which is monitored by ransomware.live, a platform that tracks the public leak pages of ransomware operations. It is important to stress that this is solely a claim made by the criminal group itself — American Casting Company has not issued any public confirmation, and no regulatory body has verified the allegation at this time.
As with many postings of this kind, the group’s site typically serves as a pressure tactic aimed at forcing payment, and the accuracy of such claims can vary widely. Until independent verification emerges, readers should treat the details as unconfirmed.
Details Currently Known vs. Details Still Unverified
- Claimed date of the incident: September 18, 2026
- Company sector: general business operations, categorized here as ‘other’
- Group making the claim: Storm, via its leak-site listing
- The specific categories of data allegedly obtained have not been disclosed by the group or confirmed by any outside party
- No statement from American Casting Company regarding this claim has been located as of this writing
What to Do if You Interact With This Company Regularly
- Update passwords tied to any accounts associated with American Casting Company, especially if reused elsewhere
- Turn on two-factor authentication wherever it is offered, including on email and financial accounts
- Be cautious of unexpected emails, texts, or calls referencing this company, particularly ones urging quick action or containing links or attachments
- Check financial and account statements periodically for unfamiliar activity
- Consider a service like a service like Aura or LifeLock that offers identity monitoring, so you can be alerted if personal information tied to you surfaces in connection with a breach
BreachLetter will revisit and update this article if American Casting Company issues a statement addressing the claim, or if the incident is disclosed to regulators or confirmed through other credible channels.