Bentley Industries Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Bentley Industries has been listed by the Interlock ransomware group, which claims to have exfiltrated internal files in an attack; the listing was reported on April 28, 2025, but the date of the actual intrusion has not been established. Individuals who may have had data with Bentley Industries should review any notices from the company and monitor their accounts for suspicious activity.
When a manufacturing company appears on a ransomware group's leak site, the immediate concern is not abstract corporate risk but the concrete possibility that employees, suppliers, dealers or customers could find their personal or business information circulating outside the organisation. On 28 April 2025 Bentley Industries, a long-established pontoon-boat manufacturer, was listed by the group known as interlock. Public detail remains limited: the number of people affected is unknown, and the only description of the material involved is that internal files were allegedly exfiltrated in a ransomware attack. For anyone whose data may have been held by the company, that listing is the starting point for practical vigilance rather than panic.
What follows is a careful account of what has been reported, what is known about the threat actor, and the steps individuals can take while fuller information is still unavailable.
Inside the incident
According to the public record, Bentley Industries was listed by the interlock ransomware group on 28 April 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the precise date of intrusion, the volume of data taken, or whether encryption of systems occurred—have been disclosed in the available facts. The number of individuals whose information may be involved is likewise unknown. In the absence of a formal statement from the company or independent confirmation, the leak-site claim remains just that: a claim by the group that it possesses and may publish the material. Public reporting has not yet established whether the files have been released or whether negotiations took place.
Inside interlock
Interlock is a ransomware operation that has been active in the public threat landscape since at least 2024. Like many contemporary groups, it typically employs a double-extortion model: data is stolen before systems are encrypted, and the threat of public release is used to pressure victims into paying a ransom. The group maintains a dedicated leak site on which it posts victim names, sometimes accompanied by sample files or countdown timers. Its targets have spanned manufacturing, professional services and other mid-sized organisations rather than only the largest enterprises. Interlock has not, in the facts available for this incident, issued any specific statements beyond the listing of Bentley Industries itself. Claims made on such sites are routinely treated by investigators as unverified until corroborated by the victim organisation, law-enforcement reporting or independent forensic analysis.
About Bentley Industries
Bentley Industries is a manufacturer of pontoon boats with more than three decades of combined experience in the recreational boating sector. The company operates a 125,000-square-foot plant in Columbia, South Carolina, a second 100,000-square-foot facility in Mexico, Missouri, and a third 90,000-square-foot plant also in Mexico, Missouri. In December 2004 it acquired Duracraft, an aluminium fishing-boat line based in Delhi, Louisiana. Its stated focus is the production of pontoon boats positioned as high-quality yet affordable for family use. Organisations of this type routinely hold employee records, supplier and dealer contact information, design and production documentation, financial data and customer order histories. A breach at such a firm therefore carries potential consequences both for the workforce and for the wider network of partners who rely on the company for boats and related services.
What was likely exposed
The only data type named in the available facts is “internal files exfiltrated in a ransomware attack.” No inventory of specific categories—such as payroll records, customer lists, engineering drawings or financial statements—has been published. Manufacturing companies of Bentley Industries’ profile typically maintain personnel files, vendor contracts, production schedules, quality-control documentation and sales records. Whether any of those categories were among the files taken remains unconfirmed. Until the company or independent investigators release a verified description, the precise contents of the exfiltrated material cannot be stated as fact.
The real-world impact
For individuals, the practical risks centre on the possible misuse of personal or business contact details, employment information or financial identifiers if those were present in the internal files. Identity-theft attempts, targeted phishing, or social-engineering approaches that reference genuine company relationships are the most common downstream effects of such incidents. For the organisation itself, the consequences can include operational disruption, reputational damage among dealers and customers, regulatory notification obligations, and the cost of forensic investigation and remediation. Because the scale of the exposure is still unknown, the breadth of these effects cannot yet be quantified. The absence of confirmed numbers does not eliminate the need for caution; it simply means responses must remain proportionate to the limited public information.
If your data was in this claimed breach
Anyone who has worked for, supplied, or purchased from Bentley Industries should treat the listing as a prompt to review account security rather than as proof of personal compromise. Begin by enabling multi-factor authentication on email and financial accounts, monitoring bank and credit statements for unexpected activity, and treating unsolicited messages that reference the company with heightened scepticism. Consider placing a fraud alert with the major credit bureaus if you believe sensitive identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a check provides an additional, independent signal while official details about this particular incident remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Print-O-Tape Listed by interlock Ransomware GroupAptura Group & Central Indiana Hardware Listed by interlock Ransomware GroupPritchard Brown & Chillicothe Metal Listed by interlock Ransomware GroupHuntwood Industries Listed by interlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Bentley Industries Listed by interlock Ransomware Group →
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.