LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › aqhch.com.cn Listed by lockbit5 Ransomware Group

HIGH severityUnverified claimHow we verify

aqhch.com.cn Listed by lockbit5 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 12, 2025
aqhch.com.cn Listed by lockbit5 Ransomware Group

Reported April 12, 2025.

HIGH
Severity
April 12, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

aqch.com.cn was listed by the LockBit 5 ransomware group on April 12, 2025, after internal files were exfiltrated in a ransomware attack. Anyone who has shared data with the organisation should verify whether their information was exposed and take steps to protect themselves.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On April 12, 2025, the domain aqhch.com.cn, associated with Heng Chang Machinery Co., Ltd, was listed by the ransomware group lockbit5. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.

For individuals or partners who may have dealt with the company, the listing raises questions about whether personal or business information could have been among the material the group claims to hold. Exact confirmation of what left the network is limited in public sources.

What happened

According to available reports, aqhch.com.cn was listed by lockbit5 on or around April 12, 2025. The group claims that internal files were taken during a ransomware attack. No public confirmation has established the precise date the intrusion began, the initial access method, the volume of data involved, or whether systems were encrypted in addition to the claimed exfiltration. The scale of any impact on employees, customers, or suppliers is listed as unknown. As with other leak-site postings, the listing itself constitutes a claim by the group rather than independently verified proof of every detail.

Who is lockbit5?

lockbit5 is associated with the LockBit ransomware operation, a well-documented cybercrime group that has operated for years under a ransomware-as-a-service model. Publicly known tactics typically include network intrusion, data theft, and threats to publish stolen material on dedicated leak sites if a ransom is not paid—a practice often called double extortion. The group has previously claimed responsibility for attacks on organizations across manufacturing, logistics, professional services, and other sectors worldwide. Its leak sites are used to pressure victims by advertising alleged breaches and, in some cases, releasing sample files. Claims made on those sites about any specific victim, including aqhch.com.cn, should be treated as assertions by the group until corroborated by independent evidence or official statements.

About aqhch.com.cn

aqhch.com.cn is the online presence of Heng Chang Machinery Co., Ltd (HCH), a Chinese manufacturer founded in 1988. Public descriptions characterize the firm as a professional manufacturer in the machinery sector, producing industrial equipment for domestic and international markets. Companies of this type commonly maintain records on employees, suppliers, customers, technical drawings, production schedules, contracts, and financial or logistics data. A breach affecting such an organization can therefore touch both internal operations and external business relationships. Because manufacturing firms often sit in extended supply chains, even limited exposure of internal files can create secondary concerns for partners who share data with them.

The information in question

Public facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No further breakdown of file types, record counts, or categories of personal data has been disclosed. Organizations in the industrial-machinery sector typically hold employee personnel files, contact details for customers and suppliers, engineering documents, purchase orders, and correspondence. Whether any of those categories were among the files the group claims to have taken remains unconfirmed. Readers should not assume specific data elements were or were not present; the public record simply does not yet establish the exact contents.

What's at stake

If internal files containing personal or commercial information were taken, affected individuals could face risks of phishing, identity misuse, or unwanted contact that leverages details from the stolen material. Business partners might see competitive or contractual information used in social-engineering attempts. For the organization itself, the incident can disrupt operations, require forensic and recovery work, and affect trust with customers and suppliers. Because the number of people affected is unknown and the precise data types remain undisclosed, the full scope of real-world harm cannot yet be measured. The primary practical concern is that any personal or sensitive business data that did leave the network may circulate further if the group releases it or if it is later traded.

What to do if you're exposed

If you have reason to believe your information may have been held by Heng Chang Machinery Co., Ltd or shared with aqhch.com.cn, take measured steps rather than reacting to unverified claims:

Public detail on this incident remains limited. Further verified information, if released by the company or independent investigators, will clarify the actual scope. Until then, calm vigilance and standard account-security practices are the most useful responses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyaqhch.com.cn security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See aqhch.com.cn’s full breach history →

More recent breaches

grupotersa.com.mx Listed by lockbit5 Ransomware GroupMarch 15, 2025topackt.com Listed by lockbit5 Ransomware GroupJanuary 15, 2025pdcm.com Listed by lockbit5 Ransomware GroupApril 28, 2025kll-law.com Listed by lockbit5 Ransomware GroupApril 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the aqhch.com.cn Listed by lockbit5 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit5 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram