Doman Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Doman was listed by the Interlock ransomware group on March 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected remains undisclosed; check Doman’s notices and change passwords or monitor accounts if you have any association with the organization.
Ransomware groups continue to target mid-sized industrial and supply-chain firms across North America, using data theft and public leak-site listings as leverage. In this environment, the appearance of a building-materials company on a ransomware group's site is a familiar pattern rather than an isolated shock. On 11 March 2025, Doman was listed by the group known as interlock, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope is limited. For employees, suppliers, retailers and others who may have shared information with the company, the listing raises practical questions about what was taken and what steps to take next.
This article sets out only what has been reported, places the claim in the context of how interlock typically operates, and explains why a breach at a vertically integrated materials supplier can matter to ordinary people even when exact data types stay undisclosed.
Inside the incident
Public reporting states that Doman was listed by the interlock ransomware group on 11 March 2025. The group claims that internal files were exfiltrated during a ransomware attack. No confirmed figure for the number of people affected has been released, and the method of initial access, the duration of any intrusion, and the exact volume of data taken remain undisclosed. The listing itself is the primary public signal; independent confirmation of the full extent of the incident has not been detailed in the available record. In short, the known facts are the date of the listing, the attribution to interlock, and the claim of internal-file exfiltration. Everything else about timing, scale and technical method is unconfirmed at this stage.
The group behind it: interlock
Interlock is a ransomware operation that has appeared in public reporting as a group that combines encryption of systems with the theft of data, then pressures victims by threatening to publish the stolen material on a dedicated leak site. Like other actors in this category, it typically posts victim names and sample claims to demonstrate possession of files and to accelerate negotiations. The group’s listings are claims made by the operators themselves; they are not independent forensic findings. Prior public activity associated with interlock has followed the double-extortion model common among contemporary ransomware crews: data is copied out before or during encryption, and the threat of public release is used as leverage. No additional statements by interlock specifically about Doman beyond the listing and the assertion of internal-file exfiltration are part of the facts provided here. Readers should therefore treat the group’s description of this incident as an unverified claim until further evidence appears.
About Doman
Doman Building Materials Group is a vertically integrated supplier of building materials headquartered in Vancouver, British Columbia, Canada. It operates distribution centres, wood-processing plants, specialty sawmills, planers and wood-cleaning facilities across North America, and holds private forest lands. The company supplies a range of products—from basic lumber to next-generation materials—to retailers throughout the region. Its model keeps it close to both the raw-material supply chain and the retail customers who sell those materials onward. Organisations of this type routinely hold operational records, supplier and customer contracts, logistics data, employee information and internal financial or planning documents. A ransomware incident that claims to have taken internal files therefore touches a business whose data flows support construction and retail activity across a wide geographic footprint. The consequential nature of any confirmed breach lies in the potential disruption to those relationships and in the sensitivity of the internal records such a firm would normally maintain.
The information in question
The facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as employee records, customer lists, financial statements or technical drawings—has been publicly named. Organisations in the building-materials sector typically store personnel files, payroll data, supplier contracts, inventory and shipping records, customer account details and internal correspondence. Whether any of those categories were among the files claimed by interlock is unconfirmed. Because the exact contents remain undisclosed, it is not possible to state with certainty what personal or commercial information left the organisation’s control. The only firm public assertion is the group’s claim that internal files were taken.
What's at stake
For individuals whose details may have been present in internal systems—employees, contractors, suppliers or retail partners—the practical risks include possible misuse of contact information, identity-related fraud if personal identifiers were included, or targeted phishing that references genuine business relationships. For the organisation itself, the stakes include operational disruption, potential contractual or regulatory follow-up, and the need to restore trust with partners who rely on the integrity of shared supply-chain data. Because the number of people affected is unknown and the precise data types are unconfirmed, the scale of these risks cannot yet be quantified. The concrete concern is simply that internal material claimed to have been stolen could be used for further criminal activity or competitive harm if it is published or sold. Calm monitoring of official statements from Doman and of any subsequent leak-site activity remains the most reliable way to gauge whether those risks materialise.
If your data was in this claimed breach
If you have a past or present relationship with Doman—as an employee, supplier, retailer or other contact—treat the incident as a prompt to review your own exposure rather than as proof that your specific records were taken. Change passwords on any accounts that may have used company-related credentials, enable multi-factor authentication where available, and watch for unexpected emails or calls that reference the company or its products. Monitor financial and credit activity for unusual behaviour. Because the exact contents of the claimed files are unconfirmed, these steps are precautionary. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets; such a scan does not confirm involvement in this particular incident but can surface other exposures that warrant attention. Stay alert for any official notices from Doman that may provide clearer guidance once more facts become public.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Janco Steel Listed by interlock Ransomware GroupDoman Building Materials Group Listed by interlock Ransomware GroupDrive Products Listed by interlock Ransomware GroupPrint-O-Tape Listed by interlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Doman Listed by interlock Ransomware Group →
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.