Automatic Systems - is a company with extremely low security of its network and products w Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Automatic Systems - is a company with extremely low security of its network and products w Listed by alphv Ransomware Group (reported June 12, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In June 2023, the ransomware group alphv publicly listed Automatic Systems, a Belgian manufacturer of secure access-control equipment, among the organisations it claimed to have attacked. The listing asserted that internal files had been taken. How many people may be touched by that claim, and exactly which records were involved, has not been made public. For employees, partners, customers, and anyone whose details sit inside a company’s internal systems, an unverified claim of this kind still raises practical questions about exposure and next steps.
Public detail remains limited. What is known comes chiefly from the group’s own leak-site notice and basic corporate information about Automatic Systems. No independent confirmation of the scale, method, or full contents of any theft has been supplied in the available record.
Breaking down the breach
According to reporting dated 12 June 2023, alphv listed Automatic Systems and stated that internal files had been exfiltrated in a ransomware attack. The group’s own headline language described the company as having “extremely low security of its network and products.” That characterisation is the group’s claim; it has not been independently verified in the material at hand.
The number of people affected is unknown. No file counts, no specific systems named beyond the general reference to internal files, and no technical description of how access was obtained appear in the disclosed facts. Timing beyond the June 2023 listing date is likewise undisclosed. In short, the public picture is that a ransomware group asserted it had stolen internal material and posted the organisation’s name; everything else about the incident itself remains unconfirmed.
Inside alphv
Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned as a ransomware-as-a-service offering. Affiliates gain access to victim networks, encrypt systems, and often exfiltrate data before encryption so they can threaten publication if a ransom is not paid. The group has been linked to numerous high-profile incidents across sectors and geographies; its leak sites have been used to name organisations and, in many cases, to release samples or larger archives of stolen data when negotiations stall.
Typical tactics associated with the group in open-source reporting include exploitation of exposed remote-access services, stolen credentials, and living-off-the-land techniques once inside a network. Double-extortion—combining encryption with the threat of data leaks—has been a hallmark. None of that general pattern should be read as a confirmed playbook for this specific listing; it simply describes how alphv has operated in documented cases elsewhere. Regarding Automatic Systems, the only concrete assertion on record is the group’s claim that internal files were taken and that the victim had been listed.
Who is Automatic Systems?
Automatic Systems designs and manufactures equipment for pedestrian, vehicle, and passenger access control. Public corporate information places its headquarters at 5 Ave Mercator, Wavre, Wallonia, 1300, Belgium, and describes it as one of the world leaders in secure access control. Its products are used in environments where physical entry and exit must be managed—transport hubs, commercial sites, and other facilities that require controlled passage.
Organisations in this sector typically hold engineering and product documentation, customer and partner records, employee information, supply-chain data, and operational details about installations. Because the company’s work sits at the intersection of physical security and networked systems, a breach claim carries weight beyond ordinary corporate data loss: it can raise questions for clients who rely on the integrity of access-control hardware and software, and for staff and contractors whose personal or professional information may reside in internal repositories.
What was likely exposed
The facts state only that internal files were exfiltrated in a ransomware attack. No inventory of those files—no categories such as customer databases, source code, financial records, or employee directories—has been published in the available material. Exact contents are therefore unconfirmed.
Companies of this type commonly store design and manufacturing documents, configuration and support data for installed systems, commercial contracts, and ordinary business records containing names, contact details, and sometimes identity or payment information. It is reasonable to expect that some mix of those materials could exist inside an “internal files” collection, but it would be inaccurate to treat any specific category as proven in this incident. Until a fuller disclosure appears, the prudent stance is that the scope is unknown and that anyone with a relationship to the company should treat the possibility of exposure as open rather than settled.
What's at stake
For individuals, the concrete risks depend on what was actually taken. If employee or contractor records were among the files, identity and contact data could be misused for phishing or social engineering. If customer or partner information was included, the same concerns apply to those organisations and their staff. Even technical or operational documents can be leveraged by criminals to craft more convincing follow-on attacks against the company or its clients.
For Automatic Systems itself, a public ransomware listing can damage trust with buyers of access-control systems, invite scrutiny from partners, and create operational and legal follow-on costs—notification duties, forensic work, and remediation—regardless of whether a ransom was paid or systems were encrypted. Because the company operates in physical security, reputational questions about the security of its own networks can matter as much as the data loss. None of these outcomes is confirmed by the thin public record; they are the ordinary consequences that follow when a ransomware group names a firm and claims to hold its files.
Were you affected?
If you work for Automatic Systems, have been a customer or partner, or otherwise shared personal or business information with the company, treat the June 2023 listing as a signal to stay alert rather than as proof that your data is already circulating. Watch for unexpected messages that reference the company or access-control projects, and avoid clicking links or opening attachments from unfamiliar senders. Consider changing passwords on accounts that may have been used in related systems, and enable multi-factor authentication where it is available. Keep an eye on financial and identity-monitoring tools if you have reason to believe sensitive personal details were held by the organisation.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can show whether your address has surfaced elsewhere and help you prioritise further precautions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
3-D Engineering/ 3-D Precision Machine Listed by alphv Ransomware GroupSAGAM Groupe - a company with dozens of vulnerabilities in its network has been hacked and Listed by alphv Ransomware GroupSMS-SME was hacked. A huge amount of confidential information was stolen, information of c Listed by alphv Ransomware GroupSMS-SME refused to protect customer and business data Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.