Comtek Advanced Structures, a Latecoere Company Listed by 8base Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Comtek Advanced Structures, a Latecoere Company Listed by 8base Ransomware Group (reported October 10, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Comtek Advanced Structures, a Latecoere company that designs, manufactures and repairs composite components for business jet and regional aircraft, was listed by the 8base ransomware group in a report dated October 10, 2023. Public detail states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further specifics about timing, method and exact contents have not been disclosed.
For an organisation that supplies aircraft OEMs and supports regional fleets with structural components used on thousands of aircraft, any confirmed or claimed exposure of internal material carries practical consequences for the business, its partners and anyone whose information may have been held in those systems. What follows summarises only what is known from the available record and established public background on the actor and sector.
What happened
According to the reported record, Comtek Advanced Structures appeared on a listing associated with the 8base ransomware group on or about October 10, 2023. The available summary states that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of people affected. Details such as the precise date the intrusion began, how access was obtained, the volume of data taken, any ransom demand, or whether systems were encrypted in addition to exfiltration have not been disclosed in the facts provided. The listing itself constitutes a claim by the group rather than an independently confirmed account of every asserted detail.
In short, the core known elements are the organisation named, the reporting date, attribution to 8base as the claiming party, and the description of internal files exfiltrated. Everything beyond that remains unconfirmed in the public record summarised here.
Inside 8base
8base is a ransomware operation that became more widely visible in public reporting from 2022 onward. Like many contemporary groups, it has been associated with double-extortion tactics: encrypting systems where possible while also copying data and threatening to publish or auction it if payment is not made. The group has typically advertised victims on a dedicated leak site, posting company names, sometimes sample files, and countdowns or statements intended to pressure organisations into negotiating.
Public analyses of 8base activity have described the use of relatively common initial-access paths seen across the ransomware ecosystem—such as compromised credentials, exposed remote services, or phishing—followed by lateral movement, data staging and exfiltration before ransomware deployment. The group has targeted organisations across multiple sectors rather than focusing exclusively on one industry. None of that general pattern should be read as a verified technical reconstruction of the Comtek incident; it is background on how 8base has operated in other publicly documented cases. With respect to this victim, the facts support only that the group listed Comtek Advanced Structures and claimed internal files were exfiltrated.
Comtek Advanced Structures and its sector
Comtek Advanced Structures designs, manufactures and repairs composite components for business jet and regional aircraft. It supplies aircraft original equipment manufacturers with composite panels and aero-engine OEMs with composite components, and it supports regional aircraft fleets with rapid repair services for structural parts. The organisation describes itself as a leading global supplier of composite components and repair services to those markets, with structural components used on thousands of aircraft worldwide. It is identified as a Latecoere company.
Aerospace supply-chain and MRO (maintenance, repair and overhaul) firms typically sit at the intersection of engineering data, production schedules, quality and certification records, customer and supplier contracts, and employee or contractor information. Because their work touches flight-critical structures and regulated manufacturing processes, even internal operational files can include material that partners, regulators or competitors would treat as sensitive. A claimed breach in this sector therefore raises questions not only about personal data but also about intellectual property, supply-chain continuity and the integrity of information shared across OEM and operator networks. Public detail does not establish what, if anything, beyond “internal files” left Comtek’s control.
What data was at risk
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of categories such as employee personal data, customer lists, engineering drawings, financial records or credentials have been provided in the available summary. The number of people affected is explicitly unknown.
Organisations of this kind commonly hold engineering and manufacturing data, quality and compliance documentation, commercial correspondence with OEMs and operators, and ordinary corporate records covering staff, contractors and vendors. It is reasonable to note that such categories often exist inside aerospace suppliers; it is not reasonable to assert that any specific category was present in the exfiltrated set. Exact contents remain unconfirmed.
Why it matters
When internal files are claimed to have been taken, the practical risks fall on several groups. Individuals whose names, contact details, identification numbers or employment information may have been stored could face phishing, social-engineering or identity-related misuse if that material later circulates. Business partners and OEMs may need to assess whether shared technical or commercial information was among the files and whether any follow-on fraud or competitive exposure is plausible. The organisation itself faces operational disruption, potential regulatory notification duties depending on jurisdiction and data types, and the longer task of verifying what left its environment and restoring confidence with customers who rely on its components and repair services.
Because the scale and precise contents are undisclosed, the severity for any single person or partner cannot be quantified from the public facts alone. The incident still matters as a concrete illustration of how ransomware groups target specialised industrial suppliers whose day-to-day work involves both proprietary technical material and ordinary personal and commercial records.
What to do if you're exposed
If you have a past or present connection to Comtek Advanced Structures—as an employee, contractor, customer contact or supplier—and you are concerned your information may have been involved, take straightforward steps. Monitor financial and email accounts for unexpected activity. Treat unsolicited messages that reference the company or the incident with caution, and verify any request for personal data or payment through a separate known channel. Consider placing fraud alerts or credit freezes where those tools are available in your country if you believe identity data could be at risk. Change passwords on accounts that may have shared credentials or been used for work-related access, and enable multi-factor authentication where it is offered.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That check will not confirm or deny involvement in this specific incident, but it can indicate whether your address has surfaced elsewhere and help you prioritise further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
JAI A/S Listed by 8base Ransomware GroupAPS - Automotive Parts Solutions Listed by 8base Ransomware GroupSCHUMAG AKTIENGESELLSCHAFT Listed by 8base Ransomware GroupRinghoffer Verzahnungstechnik GmbH and Co. KG Listed by 8base Ransomware GroupLatest breaches
Publicly posted by 8base — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.