Doman Building Materials Group Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Doman Building Materials Group was listed by the interlock ransomware group on March 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals who may have had records with the company should verify their status and consider protective steps.
Doman Building Materials Group, a Vancouver-based supplier of lumber and building products across North America, was listed on March 11, 2025, by the ransomware group known as interlock. Public reporting indicates the group claims to have carried out a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and further operational details have not been disclosed.
For an organisation that sits at the centre of construction-supply chains, any confirmed or claimed compromise of internal systems raises practical questions about the security of operational data, supplier relationships and the personal information that such firms typically process. At present the available record consists largely of the listing itself and the company’s own public description of its business.
Breaking down the breach
According to the reported summary, Doman Building Materials Group was named by interlock in connection with a ransomware attack in which internal files were said to have been exfiltrated. The listing was reported on March 11, 2025. No public figures have been released for the volume of data taken, the precise systems affected, the duration of any intrusion, or the method of initial access. The number of individuals whose information may have been involved is listed as unknown. Beyond the claim of internal-file exfiltration, the technical timeline and scope of the incident remain undisclosed.
Ransomware incidents of this type commonly involve encryption of systems combined with data theft, after which the operators demand payment under threat of publication. In this case the only concrete assertion available is the group’s listing of the company and the statement that internal files were removed. No independent confirmation of the full extent of the intrusion has been published in the materials provided.
The group behind it: interlock
Interlock is a ransomware operation that has appeared in public reporting since 2024. Like many contemporary groups, it is associated with double-extortion tactics: encrypting victim systems while simultaneously copying data and threatening to release it on a dedicated leak site if a ransom is not paid. The group has previously claimed responsibility for attacks against organisations in multiple sectors, typically advertising those claims through its own dark-web portal. Public analyses describe interlock as using standard ransomware toolkits, phishing or vulnerability exploitation for initial access, and subsequent lateral movement to locate high-value data.
In the present matter the group’s leak-site listing constitutes a claim rather than independently verified fact. No additional statements attributed specifically to interlock about Doman Building Materials Group—such as sample file listings, ransom demands or publication deadlines—appear in the available record. The listing should therefore be treated as an unverified assertion pending further disclosure by the company or law-enforcement sources.
Who is Doman Building Materials Group?
Doman Building Materials Group describes itself as a vertically integrated global building-materials company headquartered in Vancouver, British Columbia. It supplies a range of products—from basic lumber to specialised next-generation materials—to retailers across North America. The firm operates distribution centres, wood-processing plants, specialty sawmills, planers and wood-cleaning facilities, and holds private forest lands. This integrated model is intended to give the company close control over its supply chain and to maintain direct relationships with retail customers.
Organisations of this type routinely handle procurement records, logistics data, customer and supplier contact details, employee information, financial documents and operational plans. Because the company sits between forest resources and retail outlets, a disruption or data exposure can affect not only its own operations but also the wider construction-materials market in the regions it serves. The consequential nature of any breach therefore stems from both the sensitivity of internal corporate files and the firm’s position in critical supply chains.
What data was at risk
The only data category named in the public record is “internal files” said to have been exfiltrated during the ransomware attack. No further breakdown—such as whether those files contained employee records, customer lists, financial statements, contracts or operational schematics—has been disclosed. The number of people potentially affected is explicitly listed as unknown.
Companies in the building-materials sector typically maintain databases of employee personal information, payroll data, supplier contracts, customer purchase histories, shipping manifests and proprietary process documentation. While such categories are common, it is not possible to confirm that any specific type of record was among the files claimed by interlock. Exact contents therefore remain unconfirmed.
The real-world impact
For individuals whose information may have been present in internal files, the primary risks are identity-related misuse, targeted phishing that references genuine company details, and potential exposure of contact or employment data. Because the scale is unknown, the practical exposure for any single person cannot yet be quantified. Employees, contractors and business partners of Doman Building Materials Group are the groups most likely to appear in corporate internal records.
For the organisation itself, a ransomware incident can interrupt production and distribution, impose recovery costs, and create temporary uncertainty among retailers who rely on timely supply. Even when systems are restored, the claimed exfiltration of internal files can lead to longer-term concerns about competitive information or contractual details entering the public domain. No confirmed financial losses, operational downtime figures or regulatory actions have been reported in the available facts.
Were you affected?
If you are a current or former employee, contractor or business partner of Doman Building Materials Group, monitor financial and email accounts for unusual activity and treat unsolicited messages that reference the company with caution. Consider placing fraud alerts with credit bureaus if you believe personal identifiers may have been involved. Because the precise contents of the claimed data set remain undisclosed, these steps are precautionary rather than evidence of confirmed compromise.
Readers can also run a free exposure scan of their email address against known breach data sets to determine whether that address has already appeared in previously published collections. Such a check does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for personal monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Janco Steel Listed by interlock Ransomware GroupDoman Listed by interlock Ransomware GroupDrive Products Listed by interlock Ransomware GroupPrint-O-Tape Listed by interlock Ransomware GroupLatest breaches
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.