NTN Bearing Corporation of America Listed by payoutsking Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
NTN Bearing Corporation of America has been listed by the payoutsking ransomware group, with internal files reported as exfiltrated. The incident was disclosed on May 13, 2026; anyone connected to the company should verify whether their information was involved and take protective steps.
What happened
The only confirmed public information is the May 13, 2026 listing itself. The group claims that internal files were exfiltrated during a ransomware attack on NTN Bearing Corporation of America. No statement from the company has been referenced in available reporting, and details such as the date of the intrusion, the volume of data, or whether any ransom demand was issued or met are not disclosed.
Who is payoutsking?
Payoutsking is a ransomware group that follows the common pattern of encrypting systems and threatening to publish stolen data unless payment is received. These groups typically maintain leak sites where they list claimed victims and sometimes post samples of material. The listing of NTN Bearing Corporation of America constitutes the group's claim; no independent confirmation of the underlying access or data has been reported.
About NTN Bearing Corporation of America
NTN Bearing Corporation of America is the U.S. subsidiary of Japan's NTN Corporation and operates in the industrial manufacturing sector. It produces and distributes precision bearings, driveshafts, and related mechanical components used in automotive, aerospace, and industrial machinery applications. The company is headquartered in Mount Prospect, Illinois, and provides engineering support and distribution services across North America. Organizations in this sector routinely maintain records on suppliers, customers, employees, and technical specifications tied to product design and quality control.
What was likely exposed
The listing refers to internal files exfiltrated in a ransomware attack. The exact categories of data contained in those files have not been disclosed. Companies of this type commonly hold employee records, customer and supplier contact information, financial documents, and engineering or production data. Without additional public statements, the specific contents remain unconfirmed.
Why it matters
Even when the precise data types are unknown, exposure of internal files from a manufacturing firm can affect operational continuity and the privacy of individuals whose records are held by the company. In sectors that support critical supply chains, such incidents may also prompt reviews of downstream security practices. Individuals have limited direct visibility into whether their information was included until further details emerge or monitoring services report matches.
What to do if you're exposed
Anyone concerned about possible exposure should monitor official statements from NTN Bearing Corporation of America and consider placing fraud alerts with credit bureaus. Changing passwords for any accounts linked to the company and enabling multi-factor authentication where available are standard first steps. Readers can run a free exposure scan of their email address to check whether their information has surfaced in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Lc Industries Listed by payoutsking Ransomware GroupKichler Lighting Listed by payoutsking Ransomware GroupPowell Electronics Listed by payoutsking Ransomware GroupWelldyne Listed by payoutsking Ransomware GroupLatest breaches
Publicly posted by payoutsking — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.