ACDC Express Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ACDC Express was listed by the lynx ransomware group on February 14, 2025, after internal files were taken in a ransomware attack. Individuals should check whether their information was among the data exposed and take steps to protect themselves.
Ransomware groups continue to pressure organisations across manufacturing and distribution by combining encryption with data theft and public leak-site listings. In this environment, even a single claim can leave customers, staff and partners uncertain about what may have left the network.
On 14 February 2025, the ransomware group lynx listed ACDC Express on its leak site, asserting that internal files had been exfiltrated in a ransomware attack. The number of people affected remains unknown, and public detail about the incident is limited. The listing itself is a claim by the group rather than an independently confirmed disclosure.
Breaking down the breach
According to the available record, ACDC Express was listed by the lynx ransomware group on 14 February 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No further public detail has been provided on the precise timing of the intrusion, the initial access method, the volume of data taken, or whether systems were encrypted. The number of individuals potentially affected is listed as unknown. Beyond the group’s assertion that internal files were removed, the exact scope of the incident has not been confirmed in the public record.
Who is lynx?
Lynx is a ransomware operation that became publicly visible in 2024. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Affiliates associated with such groups often gain initial access through phishing, compromised credentials or unpatched remote services, then move laterally before deploying ransomware and exfiltrating files. Lynx has previously listed organisations across multiple sectors on its site. In this case, the listing of ACDC Express constitutes a claim by the group; it does not by itself constitute independent verification of the full extent of any compromise.
Who is ACDC Express?
Public information associated with the organisation describes an established South African manufacturer, importer and distributor operating in the electrical, electronics, pumps and tools industries. The company is reported to have been founded in 1984, to employ more than 700 staff, and to maintain its head office in Edenvale, Johannesburg, with additional branches in Germiston, Cape Town, Pinetown and Riverhorse in KwaZulu-Natal. Its manufactured range is said to include transformers, power supplies, electronic timers, distribution boards, motor starters, motor control centres and power-factor correction systems, along with distribution of Rhomberg Electronics products since 2006. Organisations of this type typically hold supplier and customer records, employee data, technical documentation, commercial contracts and operational systems that support manufacturing and logistics. A ransomware incident affecting such a firm can therefore have consequences for both internal operations and external partners who rely on continuity of supply.
What was likely exposed
The public record states only that internal files were exfiltrated in a ransomware attack. Specific data categories, file names, volumes or individual records have not been disclosed. Organisations in manufacturing and wholesale distribution commonly store employee personal information, payroll and HR records, customer and supplier contact details, order histories, technical drawings, pricing and commercial agreements, and system credentials or configuration data. Whether any of these categories were among the files claimed by lynx remains unconfirmed. Until more precise information is released by the organisation or verified independently, the exact contents of the exfiltrated material cannot be stated as fact.
What's at stake
For individuals whose details may have been among internal files, risks include phishing or social-engineering attempts that reference genuine company relationships, potential misuse of personal or employment data, and longer-term exposure if credentials or contact information appear in subsequent criminal markets. For the organisation, the immediate stakes involve possible disruption to manufacturing and distribution operations, the need to investigate and contain any remaining access, notification and support obligations toward staff and partners, and reputational and contractual pressure arising from a public ransomware claim. Because the scale of the incident and the precise data types remain undisclosed, the full practical impact cannot yet be quantified.
Were you affected?
If you are a current or former employee, customer or supplier of ACDC Express, treat any unexpected messages that reference the company with caution and verify them through known official channels. Monitor financial and email accounts for unusual activity, and consider changing passwords that may have been reused across work and personal services. Because the number of people affected and the exact data involved are still unknown, it is prudent to remain alert rather than assume either full exposure or complete safety. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
simmerscrane.com Listed by lynx Ransomware Groupsaacke.com Listed by lynx Ransomware Groupolarra Listed by lynx Ransomware Groupwww.medwayplastics.com Listed by lynx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ACDC Express Listed by lynx Ransomware Group →
Publicly posted by lynx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.