FBC Listed by Deadlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
FBC has been listed by the Deadlock ransomware group, with the incident disclosed on 24 August 2026. An undisclosed number of people may have had personal data exposed; anyone connected to FBC should check their status and take protective steps.
A ransomware group known as Deadlock has listed the Furniture Bargaining Council (FBC) of South Africa on its leak site, according to a report dated 24 August 2026. Nobody has confirmed that a breach occurred. The company has not publicly confirmed the claim as of writing, and public detail on what — if anything — was taken remains limited. For employers and employees who rely on FBC for industry tariffs, legal processes and administration across several provinces, the practical question is simple: if personal or workplace records were copied, what should they watch for and what can they do next.
Listings of this kind are accusations used to pressure organisations. They are not independent verification. Scale, method and exact contents are undisclosed in the material available here. Readers should treat the claim as unresolved until FBC, a regulator or another authoritative source says otherwise.
Inside the listing
Deadlock has listed FBC on its leak site. The reported summary identifies the organisation as the Furniture Bargaining Council in South Africa — the tariff council for the furniture, mattress and upholstery industry — and notes that its platform serves employers and employees in regions including Gauteng, North West, Mpumalanga, Limpopo and the Free State for legal and administrative processes. The number of people who might be affected is unknown. Data types named as exposed are not disclosed. Timing of any alleged intrusion, technical method and whether any files were actually published are not established in the available facts.
A leak-site entry does not by itself prove that systems were compromised, that data left the organisation, or that the volume or sensitivity matches whatever marketing text a group may post. Until there is confirmation from the organisation or an official body, the listing remains an unverified claim by the group that posted it.
Inside Deadlock
Deadlock is known publicly as a ransomware and extortion operation. Groups in this category typically claim to encrypt systems or steal copies of data, then threaten to publish material on a dedicated leak site if a ransom is not paid. They often list victim names, sometimes with sample files or descriptions intended to increase pressure. Public reporting on such crews generally describes double-extortion patterns: disruption inside the target environment paired with the threat of exposure.
None of that general pattern proves what happened in this specific case. For FBC, the only incident-specific point in the facts is that Deadlock has listed the organisation. Any assertion by the group about files, internal access or industry data should be read as the group’s claim, not as an audited inventory. Attribution on criminal leak sites can also be wrong, recycled or inflated; independent confirmation is what turns a listing into an established incident.
Who is FBC?
FBC, as described in the reported summary, is the Furniture Bargaining Council in South Africa. It functions as the tariff council for the furniture, mattress and upholstery industry. Its platform is used by employers and employees to handle legal and administrative processes in provinces such as Gauteng, North West, Mpumalanga, Limpopo and the Free State.
Bargaining councils in South African industrial sectors typically sit between organised labour and employers. They may administer collective agreements, dispute processes, industry funds, registrations and related compliance work. Because they sit at the centre of employment and industry administration, a claimed compromise of such a body could matter to many workplaces even when the council itself is not a household consumer brand. That consequence is why a leak-site claim draws attention — not because the claim is proven.
The information in question
The facts state that data types named as exposed are not disclosed. It is therefore not possible to say from the public listing material what fields or documents, if any, were involved. Asserting a specific inventory would go beyond what is known.
If files from an organisation of this kind were ever taken, bodies in the same role typically hold records tied to employers and employees: identity and contact details, employment or membership identifiers, correspondence about disputes or compliance, banking or contribution details for industry funds, and documents used in legal or administrative workflows. That is a description of sector norms, not a statement that any of those categories were copied from FBC. Exact contents in this matter remain unconfirmed.
The real-world impact
For people who interact with FBC, the realistic risks are conditional. If personal or employment-related data may have been exposed, common follow-on problems can include targeted phishing that references real workplace or industry details, attempts to reset accounts using known email addresses, and fraud that misuses identity or payroll-related information. Employers in the furniture, mattress and upholstery sector might face similar social-engineering risk if company contacts or administrative files were among any material taken.
For the organisation, an extortion listing can mean reputational pressure, operational distraction and the need to investigate whether systems were touched at all. None of that establishes negligence or confirms loss. The listing alone does not tell the public whether backups were affected, whether encryption occurred, or whether any third party received usable data. Impact assessments belong to a claimed incident response, which has not been established here.
People should also remember that older breaches elsewhere can recycle the same names and emails. A new listing does not automatically mean fresh exposure of every individual connected to the industry.
What to do now
Treat the situation as a caution, not as proof that your records are public. If you are an employer or employee who uses FBC services, watch for unexpected messages that cite industry tariffs, disputes, contributions or council processes, and verify any request through official channels you already trust. Prefer unique passwords and multi-factor authentication on email and HR-related accounts. If you see charges, account changes or identity alerts you did not initiate, contact your bank or the relevant institution directly using published contact details.
FBC has not publicly confirmed the claim as of writing. Follow only notices that come from the council or competent authorities if they appear. As a practical check on whether your email address has already appeared in known breach datasets from other incidents, you can run a free exposure scan of your email and then tighten credentials on any accounts that show up.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ufoc Listed by Deadlock Ransomware GroupFiresta Listed by Deadlock Ransomware GroupJoso Listed by Deadlock Ransomware Group8.2 Group e.V. Listed by Deadlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the FBC Listed by Deadlock Ransomware Group →
Publicly posted by deadlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.