LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ShapeCorp Listed by nova Ransomware Group

HIGH severityUnverified claimHow we verify

ShapeCorp Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 11, 2025
ShapeCorp Listed by nova Ransomware Group

Reported October 11, 2025.

HIGH
Severity
October 11, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ShapeCorp was listed by the nova ransomware group on October 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected is undisclosed; anyone who may have shared data with ShapeCorp should review their accounts and monitor for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target industrial and manufacturing firms that hold valuable engineering and production data, using double-extortion tactics that combine encryption with public leak-site listings. In this environment, even a single listing can signal potential exposure of sensitive internal material long before full details emerge.

On 11 October 2025, the ransomware group known as nova listed ShapeCorp on its leak site, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise timeline and method is limited. The listing itself is an unverified claim by the group.

Breaking down the breach

According to the available record, ShapeCorp was listed by the nova ransomware group on 11 October 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No confirmed figures have been released for the volume of data taken, the duration of any intrusion, or the specific entry vector used. Public reporting does not establish whether systems were encrypted, whether a ransom demand was made, or whether the company has verified the authenticity of the claimed material. The only concrete assertion at this stage is the leak-site listing itself and the description of the data as internal files obtained through ransomware activity.

Inside nova

Nova is a ransomware operation that has appeared in public reporting as a group employing double-extortion methods: encrypting victim systems while also copying data and threatening to publish it on a dedicated leak site if payment is not made. Like other actors in this category, nova typically advertises victims on its site with sample files or file-tree listings to pressure organisations. The group’s listings are claims rather than independently verified disclosures; they serve as both advertisement and leverage. Prior public activity associated with similar groups has focused on mid-sized and larger enterprises holding proprietary technical or commercial information, though each incident must be assessed on its own evidence. In the present case, the sole documented link is nova’s claim that ShapeCorp data was taken and listed.

ShapeCorp and its sector

ShapeCorp, also referred to as Shape Corp., operates as a global supplier in automotive engineering and manufacturing. The company specialises in advanced crash-management systems and body-structure solutions that use ultra-high-strength steel roll forming, tight-tolerance aluminium extrusions and large-tonnage injection moulding. Its products are designed to be lightweight and performance-oriented while reducing environmental impact. Organisations of this type sit deep in automotive supply chains, holding detailed engineering data, production tooling information and commercial arrangements with vehicle manufacturers. A breach involving such a firm can therefore affect not only the company itself but also the integrity of design and manufacturing processes shared with partners across the sector.

The information in question

The facts state that internal files were exfiltrated. The group’s listing further claims that the extracted material includes engineering design files, marketing and presentation assets, CAD files, mechanical designs, CNC programs, project documentation, automation data, brand media, financial records and production-related material. Exact file counts, date ranges and whether any personal data of employees or customers were included remain undisclosed. Organisations in automotive engineering typically maintain precisely these categories of proprietary technical and commercial information; however, until independent confirmation is available, the precise contents and scope of any exposure stay unconfirmed beyond the group’s claims.

What's at stake

For ShapeCorp, the principal risks centre on the potential loss of competitive advantage if proprietary designs, CNC programs or automation data become available to rivals or unauthorised parties. Financial and project documentation could also reveal commercial terms or cost structures. For individuals whose information may appear in internal files—employees, contractors or contacts—the usual concerns apply: possible misuse of contact details, credentials or other personal identifiers if such data were present. Because the number of people affected is unknown and the full data set is unconfirmed, the scale of personal impact cannot yet be quantified. Supply-chain partners may also face secondary risk if shared engineering files were among those claimed.

If your data was in this claimed breach

If you have a connection to ShapeCorp—as an employee, contractor, supplier or customer—consider the following practical steps while official confirmation remains limited:

Continue to watch for official statements from ShapeCorp or relevant authorities. Until more verified detail is released, treat the nova listing as a claim rather than confirmed fact, and focus on the protective measures that remain under your control.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyShapeCorp security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See ShapeCorp’s full breach history →

More recent breaches

Shape Corp Listed by nova Ransomware GroupOctober 8, 2025Epcatalogs Company Listed by nova Ransomware GroupJune 29, 2025hasbco Company Listed by nova Ransomware GroupApril 10, 2025Textile Testing Services of America Listed by nova Ransomware GroupMay 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the ShapeCorp Listed by nova Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by nova — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram