Ess Brothers & Sons Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Ess Brothers & Sons was listed by the dragonforce ransomware group on June 17, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to the company should check whether their information was involved and take appropriate protective steps.
Ess Brothers & Sons, a long-established U.S. manufacturer, was listed by the dragonforce ransomware group on June 17, 2025. Public reporting indicates the group claims to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and further technical details about the intrusion have not been disclosed.
The listing itself is an unverified claim by the threat actor. What is known so far is limited to the group's public assertion of data theft and the company's historical profile as a multi-generational supplier of municipal cast products. For customers, employees, and partners, the incident raises questions about the security of internal business records even though the precise scope of exposure has not been confirmed.
Inside the incident
According to available reports, Ess Brothers & Sons appeared on a dragonforce leak site on June 17, 2025. The group stated that internal files had been exfiltrated as part of a ransomware attack. No public confirmation has been issued by the company regarding the accuracy of that claim, the method of initial access, the duration of unauthorized presence, or whether systems were encrypted. The number of people affected is listed as unknown, and no file counts, sample data, or ransom demands have been detailed in the public record.
Because the only concrete assertion comes from the threat actor's listing, independent verification of the breach's scale and contents is not yet available. Timing beyond the June 17 reporting date, the specific ransomware variant used, and any negotiation or recovery steps remain undisclosed. In short, the incident is known primarily through the group's claim of internal-file exfiltration rather than through detailed forensic disclosures.
Who is dragonforce?
Dragonforce is a ransomware group that has operated in the public eye as a ransomware-as-a-service operation. Like many contemporary groups, it typically employs double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. The group has been observed listing victims across manufacturing, professional services, and other sectors, often posting proof-of-compromise samples to pressure organizations.
Public reporting on dragonforce describes a model in which affiliates gain initial access—commonly through phishing, exploited vulnerabilities, or compromised remote-access tools—then deploy the ransomware payload and exfiltrate data. The group maintains a leak site where it claims responsibility and, in some cases, releases stolen files. These practices are well-documented across multiple incidents; however, any specific statements dragonforce has made about Ess Brothers & Sons beyond the bare listing of the company and the assertion of internal-file theft should be treated strictly as the group's claim rather than established fact.
About Ess Brothers & Sons
Ess Brothers & Sons is a family-owned manufacturer whose roots date to 1867, when Joseph Ess established a blacksmith and wagon shop. Over successive generations the business evolved: Frank Ess created a foundry, and later owners Edmund and Wallace expanded into supplying municipal cast products. The company is now in its sixth generation of ownership under Troy and Trent Ess, continuing a tradition of producing and sourcing products for clients. Its stated mission emphasizes honorable service, meeting or exceeding customer needs, and fabricating items when stock is unavailable.
Organizations of this type typically operate in the industrial-supply and municipal-infrastructure sector, manufacturing or distributing cast-iron components such as manhole covers, grates, and related hardware used by cities, utilities, and contractors. They commonly maintain records of customer orders, supplier contracts, employee information, engineering drawings, and financial data. A breach at such a firm is consequential because the data often includes both commercial relationships and personal details of staff and clients, and because disruption can affect municipal supply chains that rely on timely delivery of specialized cast products.
What data was at risk
The only data type named in public reporting is "internal files" said to have been exfiltrated in the ransomware attack. No further breakdown—such as employee records, customer lists, financial documents, or intellectual property—has been disclosed. The number of individuals potentially affected is unknown.
Companies in the municipal-cast and industrial-supply sector ordinarily hold a range of sensitive information: payroll and human-resources files, customer purchase histories and contact details, vendor contracts, engineering specifications, and internal correspondence. Whether any of those categories were among the files claimed by dragonforce remains unconfirmed. Until the company or independent investigators release a verified inventory, the exact contents of the exfiltrated material cannot be stated as fact.
The real-world impact
For individuals whose information may have been included in the internal files, the primary risks are the usual consequences of corporate data exposure: possible misuse of personal identifiers for phishing, identity fraud, or social-engineering attempts. Because the precise data types are unconfirmed, the severity for any given person cannot yet be quantified. Employees and long-term customers of a multi-generational firm may find that historical records spanning decades are involved, increasing the chance that older but still sensitive details surface.
For Ess Brothers & Sons itself, the claimed exfiltration raises operational and reputational concerns. Even if systems were restored quickly, the potential publication of internal files could reveal pricing, supplier relationships, or proprietary processes. Municipal clients that depend on the company's cast products may need to reassess supply-chain security, while the firm faces the ordinary costs of investigation, notification, and remediation. None of these outcomes has been publicly detailed; they remain the logical consequences of a ransomware claim involving internal-file theft rather than confirmed events.
What to do if you're exposed
If you have a past or present relationship with Ess Brothers & Sons—as an employee, customer, or vendor—treat the possibility of exposure seriously even while details remain limited. Monitor financial and credit accounts for unexpected activity, enable multi-factor authentication on email and other critical services, and be alert to phishing messages that reference the company or its products. Consider placing a fraud alert or credit freeze if you believe personal identifiers may have been involved. Because the exact data set is unconfirmed, these steps are precautionary rather than responses to a verified personal breach.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan provides an additional data point but does not replace vigilance or official notifications that may eventually come from the company itself. Stay informed through reputable sources and avoid acting on unverified claims circulating on social media or leak sites.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Burnex Listed by dragonforce Ransomware GroupBarnes & Jones Listed by dragonforce Ransomware GroupMullinax Ford Listed by dragonforce Ransomware GroupTri-State Metal Roofing Supply Listed by dragonforce Ransomware GroupLatest breaches
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.