LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › North American Spares Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

North American Spares Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 27, 2025
North American Spares Listed by dragonforce Ransomware Group

Reported January 27, 2025.

HIGH
Severity
January 27, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

North American Spares has been added to the data-leak site operated by the dragonforce ransomware group, with internal files reported stolen in an attack. The incident was disclosed on 27 January 2025; the exact date of the intrusion is not established. Individuals should check whether their information may have been exposed and take appropriate steps to protect themselves.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On January 27, 2025, North American Spares was listed by the dragonforce ransomware group. The group claims that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and public detail on the full scope of the incident is limited.

North American Spares supplies strategic turn-key solutions for military aircraft maintenance. Any confirmed compromise of an organization in this sector can carry consequences for operational continuity and for individuals whose information may have been among the files taken.

What happened

Reports dated January 27, 2025 state that the dragonforce ransomware group listed North American Spares on its leak site. According to the listing, internal files were exfiltrated in a ransomware attack. No further public confirmation of the intrusion method, the exact date the attack began, the volume of data involved, or independent verification of the group’s claims has been disclosed. The number of people affected is listed as unknown.

Who is dragonforce?

Dragonforce is a ransomware group that has operated in the public eye by maintaining a leak site where it names alleged victims and, in some cases, publishes samples of stolen data. Like other groups that follow a double-extortion model, it typically claims to have both encrypted systems and copied files, then pressures organizations by threatening to release the material. Public reporting on the group has described it as targeting a range of commercial and industrial organizations rather than focusing exclusively on one sector. Its listings are claims made by the actors themselves; they are not independent confirmations that a breach occurred or that every asserted detail is accurate.

In this instance, the only specific assertion tied to North American Spares is the leak-site listing itself and the statement that internal files were exfiltrated. No additional quotes or technical claims about this particular victim appear in the available record.

Who is North American Spares?

North American Spares provides strategic turn-key solutions for military aircraft maintenance and offers services that extend beyond simple parts supply. Organizations of this type typically sit within the aerospace and defense supply chain, supporting maintenance, repair, and overhaul activities for military platforms. They commonly hold technical documentation, supplier and customer records, employee information, and contractual data linked to government or military customers.

A breach affecting such a firm is consequential because the data it holds can include both ordinary business records and material that, if exposed, could affect operational security, contractual relationships, or the privacy of staff and partners. Public detail does not establish that any particular category of sensitive military data was taken; it only identifies the organization and the claim of internal-file exfiltration.

What was likely exposed

The available facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, record counts, or specific data categories has been disclosed. Organizations that supply military aircraft maintenance solutions commonly maintain a mix of operational, commercial, and personnel records. Exact contents in this case remain unconfirmed.

Because the public record does not name specific data elements beyond “internal files,” any assumption that particular personal or classified information was involved would be speculative.

What's at stake

For individuals whose information may have been present in the exfiltrated files, the practical risks include potential misuse of contact details, employment data, or other personal identifiers if those records were among the material taken. Without a confirmed inventory of what was copied, the precise exposure for any one person cannot be stated.

For the organization, the stakes include disruption to maintenance and supply operations, possible contractual or regulatory scrutiny arising from a ransomware incident, and reputational effects with military and commercial partners. Ransomware events of this kind can also create secondary costs related to system recovery, legal review, and notification obligations if personal data is later confirmed to have been involved. None of these outcomes has been publicly quantified for this incident.

Were you affected?

If you are a current or former employee, contractor, supplier, or customer of North American Spares, treat the listing as a reason to remain attentive rather than as proof that your personal data was taken. Practical first steps include monitoring financial and email accounts for unusual activity, enabling multi-factor authentication where available, and being cautious of unsolicited messages that reference the company or the incident. Official notifications, if any are required, would come from the organization itself once it has assessed the data involved.

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyNorth American Spares security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See North American Spares’s full breach history →

More recent breaches

Burnex Listed by dragonforce Ransomware GroupDecember 29, 2025Barnes & Jones Listed by dragonforce Ransomware GroupDecember 27, 2025Mullinax Ford Listed by dragonforce Ransomware GroupDecember 25, 2025Tri-State Metal Roofing Supply Listed by dragonforce Ransomware GroupDecember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the North American Spares Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram