LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › A/C Supply Listed by interlock Ransomware Group

HIGH severityUnverified claimHow we verify

A/C Supply Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 9, 2025
A/C Supply Listed by interlock Ransomware Group

Reported May 9, 2025.

HIGH
Severity
May 9, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A/C Supply, Inc. was listed by the interlock ransomware group on May 09, 2025, with internal files reportedly taken during the attack. Individuals should verify whether their information was among the exposed data and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A/C Supply, Inc., a wholesale distributor of HVAC-R products serving southern Louisiana and Mississippi, has been listed by the interlock ransomware group as a victim of a cyberattack. Public reporting of the listing appeared on May 09, 2025. Available details indicate that internal files were exfiltrated during a ransomware attack, though the number of people affected remains unknown and further specifics about timing, method, or full scope have not been disclosed.

The listing itself is a claim by the group rather than an independently verified confirmation of every asserted detail. For customers, employees, and partners of a regional distributor that handles supply-chain and business records, the incident raises practical questions about what information may have left the company’s systems and what steps those potentially affected can take.

Breaking down the breach

According to the available record, A/C Supply, Inc. was listed by the interlock ransomware group in connection with a ransomware attack in which internal files were exfiltrated. The report date associated with the listing is May 09, 2025. No figure has been published for the number of individuals whose data may have been involved, and public detail does not identify the precise date of intrusion, the initial access vector, or the volume of data taken.

Ransomware incidents of this type typically involve encryption of systems combined with data theft, after which operators pressure the victim by threatening to publish or sell the stolen material. In this case the only named category of exposed material is “internal files.” Whether those files included customer records, employee information, financial documents, or operational data has not been confirmed in the public facts. No ransom demand amount, negotiation status, or confirmation of data publication has been provided in the source material.

The group behind it: interlock

Interlock is a ransomware operation that has appeared in public reporting as a relatively recent entrant among double-extortion groups. Like many such actors, it is known to combine system encryption with the theft of data, then list victims on a dedicated leak site to increase pressure. Publicly documented activity associated with the group has included targeting of organizations across multiple sectors rather than a single industry focus. Operators typically claim to have obtained sensitive internal material and threaten to release it if payment is not made.

In the present case, the group’s listing of A/C Supply, Inc. constitutes its claim that the company was successfully compromised and that internal files were taken. No independent verification of the full extent of that claim appears in the available facts, and no statements attributed specifically to interlock about this particular victim—beyond the listing itself—have been supplied. Readers should treat the leak-site entry as an unverified assertion by the threat actor until additional confirmation emerges.

About A/C Supply, Inc.

A/C Supply, Inc. is described as a leading wholesale distributor of HVAC-R products operating in southern Louisiana and Mississippi. The company maintains twelve branches across those two states and presents itself as a third-generation family business that employs staff focused on product knowledge and customer service. Organizations of this type sit in the middle of the heating, ventilation, air-conditioning, and refrigeration supply chain: they purchase equipment and parts from manufacturers and sell them to contractors, technicians, and other commercial buyers.

A regional wholesale distributor typically maintains records of customer accounts, purchase histories, pricing agreements, inventory, supplier relationships, employee information, and internal financial and operational documents. Because the business serves a defined geographic market through multiple physical locations, a compromise can affect both the company’s own operations and the contractors and end customers who rely on timely parts and equipment. The company has stated that it takes cybersecurity and its customers seriously; the current incident is the first public indication that those systems were targeted by a ransomware group.

What was likely exposed

The facts name only one category of material: internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files contained personally identifiable information, payment details, employee records, or proprietary business data—has been disclosed. The number of people affected is listed as unknown.

Wholesale HVAC-R distributors commonly hold customer contact and account information, order and invoice histories, shipping addresses, employee personnel files, vendor contracts, and internal correspondence. Any of these could theoretically have been among the internal files taken, but that remains unconfirmed. Until the company or independent investigators provide a more precise inventory, the exact contents of the exfiltrated material cannot be stated as fact.

What's at stake

For individuals whose information may have been included, the primary risks are the ordinary consequences of data exposure: potential misuse of contact details for phishing or social-engineering attempts, and, if financial or identity-related records were present, elevated risk of fraud. Because the precise data types remain undisclosed, the severity for any given person cannot yet be quantified.

For A/C Supply, Inc. itself, a ransomware incident can disrupt order processing, inventory management, and branch operations across its twelve locations. Even after systems are restored, the company may face costs related to investigation, notification, and remediation, as well as reputational questions from customers and suppliers who depend on reliable service. The absence of a published count of affected individuals or a confirmed data inventory leaves both the human and organizational impact still partially undefined.

If your data was in this claimed breach

If you have done business with A/C Supply, Inc. or believe your information may have been among the internal files, begin with basic precautions. Monitor financial accounts and credit reports for unexpected activity. Be alert to unsolicited emails, calls, or messages that reference the company or claim to offer assistance; these can be phishing attempts that exploit public knowledge of the incident. Consider placing a fraud alert or credit freeze if you later learn that sensitive personal data was involved. Change passwords on any accounts that reused credentials associated with the company, and enable multi-factor authentication wherever possible.

Because the full scope of the breach remains unconfirmed, checking whether your email address has already appeared in other known breach data sets can provide an early signal. Free exposure-scan tools allow you to enter an email address and see whether it has surfaced in previously reported incidents; such a check is a practical first step while waiting for any official notification from the company. Stay attentive to any direct communications from A/C Supply, Inc. that provide additional Reported Details about what was taken and who may be affected.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyA/C Supply, Inc. security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See A/C Supply, Inc.’s full breach history →

More recent breaches

Aptura Group & Central Indiana Hardware Listed by interlock Ransomware GroupNovember 7, 2025Print-O-Tape Listed by interlock Ransomware GroupDecember 15, 2025Pritchard Brown & Chillicothe Metal Listed by interlock Ransomware GroupOctober 29, 2025Huntwood Industries Listed by interlock Ransomware GroupAugust 25, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the A/C Supply Listed by interlock Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by interlock — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram