LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Greenfiber Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Greenfiber Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 24, 2023
Greenfiber Listed by alphv Ransomware Group

Reported July 24, 2023.

HIGH
Severity
July 24, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Greenfiber Listed by alphv Ransomware Group (reported July 24, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure organisations by pairing encryption with data theft and public leak-site postings, turning internal files into leverage and leaving customers, employees and partners to assess secondary risk. In that landscape, a July 2023 listing of Greenfiber by the alphv group fits a familiar pattern: a claim of exfiltration, a promise that material is available to download, and limited independent confirmation of scope.

Public reporting states that Greenfiber, a national manufacturer of cellulose insulation serving the United States and Canada, was named on an alphv-associated leak site. The number of people affected remains unknown, and the precise contents of any taken files have not been independently itemised beyond the general description of internal material. The episode matters because manufacturers in this sector routinely hold operational, commercial and workforce records whose exposure can create lasting practical harm even when full details stay undisclosed.

What happened

On or around 24 July 2023, Greenfiber appeared in reporting tied to a listing by the alphv ransomware group. According to the material associated with that listing, internal files were exfiltrated in a ransomware attack and the group claimed that “all data” had been published and made available for downloading. No confirmed figure for the number of affected individuals has been published. The specific intrusion method, the duration of any unauthorised access, and any ransom demand or payment outcome are not detailed in the available facts. What is on record is the claim of exfiltration of internal files and the subsequent leak-site style announcement.

Because the listing itself is an assertion by the threat actor, it should be treated as an unverified claim unless and until the organisation or independent investigators corroborate the full extent of the incident. Public summaries emphasise the industrial identity of the victim—cellulose insulation manufacturing for energy-efficient building products—rather than a granular inventory of stolen records.

Inside alphv

Alphv, also widely known in public reporting as BlackCat, has operated as a ransomware-as-a-service operation. Affiliates typically gain initial access through common enterprise weak points, move laterally, exfiltrate data, and deploy ransomware while threatening or carrying out publication on a dedicated leak site if negotiations fail. The group has been associated with double-extortion tactics: encryption paired with theft, followed by timed releases or full dumps intended to increase pressure on the victim.

Public documentation of alphv activity over multiple years describes a professionalised model—custom ransomware variants, negotiation channels, and staged leak-site posts that name organisations and sometimes sample files. Those established patterns supply context for how a listing of Greenfiber would be presented. They do not, however, prove every detail of this particular case. For Greenfiber, the facts support only that the group claimed internal files were taken and published; no further victim-specific statements beyond that claim are established here.

Who is Greenfiber?

Greenfiber is described in the available summary as a national manufacturer of cellulose insulation, offering energy-saving and cost-effective insulation products for the United States and Canada and positioning itself among leading suppliers in that product category. Organisations of this type sit in the building-materials and manufacturing supply chain. They typically manage production data, distributor and contractor relationships, logistics, quality and compliance records, and standard corporate functions such as finance, human resources and information technology.

A breach affecting such a manufacturer is consequential because insulation and related building products touch residential and commercial construction markets. Disruption or exposure can affect not only the company but also partners who rely on continuous supply, pricing, and technical documentation. Even when customer-facing consumer databases are not the primary target, internal files can still contain enough commercial and personal detail to create follow-on risk for staff, vendors and counterparties.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as employee counts, customer lists, financial ledgers, or intellectual-property categories—is provided, and the number of people affected is unknown. Exact contents therefore remain unconfirmed.

Manufacturers in the cellulose-insulation and broader building-products sector commonly hold categories of information that, if present in an internal file store, would be sensitive: workforce records, payroll and benefits data, vendor and distributor contracts, shipping and inventory systems, engineering or product specifications, internal email, and credentials or configuration details used to run plants and offices. Whether any of those categories were among the files the group claims to have published is not established by the public record summarised here. Readers should treat broad claims of “all data” as an actor assertion rather than a verified inventory.

Why it matters

For individuals whose information may have been among internal files, real-world risk includes targeted phishing that references genuine workplace or vendor details, identity fraud if government identifiers or financial data were stored, and long-term reuse of leaked credentials on other services. For the organisation, consequences can include operational disruption, regulatory notification duties where personal data is involved, contractual friction with distributors, and reputational cost among builders and partners who expect reliable handling of commercial information.

Because scale and data types beyond “internal files” are undisclosed, the prudent stance is caution without assuming the worst-case inventory. The combination of a public leak-site claim and the nature of manufacturing records is enough to justify monitoring and basic protective steps for anyone who has a past or present relationship with the company.

If your data was in this claimed breach

If you are an employee, contractor, vendor contact or other party who may appear in Greenfiber’s internal systems, treat the incident as a prompt to harden everyday defences rather than as proof that every personal record was taken. Concrete first steps include:

Public detail on this incident remains limited to the July 2023 alphv listing claim, the description of internal-file exfiltration, and the company’s identity as a cellulose-insulation manufacturer. Further clarity would depend on official statements or independent analysis that have not been supplied in the facts above. Until then, measured personal hygiene around credentials and monitoring is the practical response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyGreenfiber security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Greenfiber’s full breach history →

More recent breaches

Wesgar Inc Listed by alphv Ransomware GroupDecember 28, 2023Aura Engineering, LLC Listed by alphv Ransomware GroupDecember 27, 2023Lisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupDecember 2, 2023Dörr Group Listed by alphv Ransomware GroupDecember 1, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Greenfiber Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram