Enedo Power Listed by Deadlock Ransomware Group: What Was Exposed & What To Do
Enedo Power was listed by the Deadlock ransomware group on July 25, 2026, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to the company should check for possible exposure and secure their accounts.
When a company that supplies power systems for defence, rail and other critical infrastructure appears on a ransomware group's leak site, the immediate concern is not abstract corporate risk. It is whether internal files that left the network include names, contact details, contracts, or other records that could be misused against employees, partners or customers. Public reporting so far leaves the scale and exact contents unconfirmed, so people connected to Enedo Power — now operating as Inission Power — have limited hard information and every reason to treat the claim seriously until more is known.
On 25 July 2026, Enedo Power was listed by the Deadlock ransomware group. The listing asserts that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been published. What follows sets out only what has been reported, places the claim in context, and outlines practical steps for anyone who may be exposed.
Breaking down the breach
According to the available record, Enedo Power was named on Deadlock's leak site on 25 July 2026. The group claims that internal files were taken during a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the number of individuals whose information may appear in the material. The precise method of initial access, the duration of any intrusion, and whether encryption was also deployed on production systems have not been disclosed in the facts provided.
Because the listing originates from the threat actor, it should be treated as an unverified claim until the organisation or independent investigators corroborate it. No dollar amounts, file counts, or sample documents have been detailed in the public summary used for this account. The only concrete assertion on record is that internal files were exfiltrated and that the company was listed by Deadlock.
Inside Deadlock
Deadlock is a ransomware operation known publicly for double-extortion tactics: encrypting victim systems while also copying data and threatening to publish it if a ransom is not paid. Like other groups in this category, it typically advertises victims on a dedicated leak site, sometimes releasing samples or larger archives to increase pressure. Public reporting on Deadlock has described the use of common initial-access routes seen across the ransomware ecosystem — such as compromised credentials, exposed remote services, or phishing — followed by lateral movement and data staging before encryption or exfiltration.
Nothing in the facts supplied attributes specific technical claims by Deadlock to this particular incident beyond the listing itself and the assertion that internal files were taken. Prior activity by the group against other organisations is a matter of public cybersecurity reporting; those earlier cases do not automatically prove what occurred at Enedo Power. Readers should therefore separate the group's general reputation from the still-unverified particulars of this listing.
Enedo Power and its sector
Enedo Power, which has been renamed Inission Power, develops intelligent power-supply systems for critical infrastructure and industrial use. It is part of the Swedish Inission Group and has Finnish roots. Its products include robust power supplies, power systems and LED drivers aimed at demanding environments, among them defence and railway technology. Organisations in this sector routinely hold engineering documentation, supplier and customer records, employee information, and sometimes regulated or sensitive project data tied to infrastructure and defence-related work.
A breach affecting a supplier in this space matters because power systems sit inside larger operational chains. Disruption or exposure of internal files can affect not only the company itself but also partners who rely on its components and the confidentiality of projects that touch transport or defence. Even when the precise contents of a leak remain unconfirmed, the sector's role in critical applications raises the stakes for both operational continuity and the privacy of people whose details appear in business systems.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types — such as whether the material included human-resources records, customer lists, financial documents, source code, or technical drawings — has been disclosed. The number of people affected is unknown.
Companies of this kind typically maintain employee contact and payroll data, supplier and customer contracts, engineering and quality documentation, and internal correspondence. Some of that material may be commercially sensitive or subject to contractual confidentiality, especially where defence or rail projects are involved. Because the exact contents have not been confirmed publicly, it is not possible to state as fact which of these categories, if any, appear in the claimed exfiltration. Anyone who has worked with or for the organisation should assume that ordinary business records could be in scope until clearer inventories are released.
The real-world impact
For individuals, the practical risks of internal-file exposure include targeted phishing that references real projects or colleagues, identity misuse if personal details are present, and social-engineering attempts against partners who appear in the same documents. Even partial contact lists or organisational charts can help attackers craft convincing messages. For the organisation, consequences can include regulatory notification duties, contractual disputes with customers, reputational harm, and the cost of investigation and remediation. In a sector that serves critical infrastructure, there is also the secondary concern that technical or supply-chain information could be of interest to competitors or other hostile actors, though no such use has been documented in the facts at hand.
Because headcount and data categories remain undisclosed, the breadth of personal impact cannot be quantified. The absence of confirmed numbers does not mean the risk is zero; it means affected people must rely on caution and monitoring rather than on a definitive list of what was taken.
If your data was in this breach
If you are a current or former employee, contractor, customer or supplier of Enedo Power or Inission Power, treat the Deadlock listing as a prompt to tighten basic hygiene. Change passwords on work-related and personal accounts that may have shared credentials, enable multi-factor authentication wherever it is offered, and watch for unexpected emails or calls that reference internal projects or colleagues. Review bank and credit activity if financial or identity data could plausibly have been stored in company systems. Preserve any suspicious messages rather than deleting them, so they can be examined later if needed.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That check will not prove or disprove inclusion in this specific incident, but it can show whether your address is circulating more widely and help you prioritise further protections. Stay alert for official notices from the company; until more detail is published, measured caution is the most reliable response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Schaad Listed by Deadlock Ransomware GroupVinilon Listed by Deadlock Ransomware GroupKemek Listed by Deadlock Ransomware GroupBioResearch Listed by Deadlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Enedo Power Listed by Deadlock Ransomware Group →
Publicly posted by deadlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.