ShapeCorp Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ShapeCorp was listed by the nova ransomware group on October 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected is undisclosed; anyone who may have shared data with ShapeCorp should review their accounts and monitor for suspicious activity.
Ransomware groups continue to target industrial and manufacturing firms that hold valuable engineering and production data, using double-extortion tactics that combine encryption with public leak-site listings. In this environment, even a single listing can signal potential exposure of sensitive internal material long before full details emerge.
On 11 October 2025, the ransomware group known as nova listed ShapeCorp on its leak site, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise timeline and method is limited. The listing itself is an unverified claim by the group.
Breaking down the breach
According to the available record, ShapeCorp was listed by the nova ransomware group on 11 October 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No confirmed figures have been released for the volume of data taken, the duration of any intrusion, or the specific entry vector used. Public reporting does not establish whether systems were encrypted, whether a ransom demand was made, or whether the company has verified the authenticity of the claimed material. The only concrete assertion at this stage is the leak-site listing itself and the description of the data as internal files obtained through ransomware activity.
Inside nova
Nova is a ransomware operation that has appeared in public reporting as a group employing double-extortion methods: encrypting victim systems while also copying data and threatening to publish it on a dedicated leak site if payment is not made. Like other actors in this category, nova typically advertises victims on its site with sample files or file-tree listings to pressure organisations. The group’s listings are claims rather than independently verified disclosures; they serve as both advertisement and leverage. Prior public activity associated with similar groups has focused on mid-sized and larger enterprises holding proprietary technical or commercial information, though each incident must be assessed on its own evidence. In the present case, the sole documented link is nova’s claim that ShapeCorp data was taken and listed.
ShapeCorp and its sector
ShapeCorp, also referred to as Shape Corp., operates as a global supplier in automotive engineering and manufacturing. The company specialises in advanced crash-management systems and body-structure solutions that use ultra-high-strength steel roll forming, tight-tolerance aluminium extrusions and large-tonnage injection moulding. Its products are designed to be lightweight and performance-oriented while reducing environmental impact. Organisations of this type sit deep in automotive supply chains, holding detailed engineering data, production tooling information and commercial arrangements with vehicle manufacturers. A breach involving such a firm can therefore affect not only the company itself but also the integrity of design and manufacturing processes shared with partners across the sector.
The information in question
The facts state that internal files were exfiltrated. The group’s listing further claims that the extracted material includes engineering design files, marketing and presentation assets, CAD files, mechanical designs, CNC programs, project documentation, automation data, brand media, financial records and production-related material. Exact file counts, date ranges and whether any personal data of employees or customers were included remain undisclosed. Organisations in automotive engineering typically maintain precisely these categories of proprietary technical and commercial information; however, until independent confirmation is available, the precise contents and scope of any exposure stay unconfirmed beyond the group’s claims.
What's at stake
For ShapeCorp, the principal risks centre on the potential loss of competitive advantage if proprietary designs, CNC programs or automation data become available to rivals or unauthorised parties. Financial and project documentation could also reveal commercial terms or cost structures. For individuals whose information may appear in internal files—employees, contractors or contacts—the usual concerns apply: possible misuse of contact details, credentials or other personal identifiers if such data were present. Because the number of people affected is unknown and the full data set is unconfirmed, the scale of personal impact cannot yet be quantified. Supply-chain partners may also face secondary risk if shared engineering files were among those claimed.
If your data was in this claimed breach
If you have a connection to ShapeCorp—as an employee, contractor, supplier or customer—consider the following practical steps while official confirmation remains limited:
- Monitor financial and credit accounts for unusual activity and enable available fraud alerts.
- Change passwords on any accounts that may have been linked to company systems, using unique credentials and multi-factor authentication where possible.
- Treat unsolicited emails or calls referencing the incident with caution; phishing often follows public breach listings.
- Request a free exposure scan of your email address against known breach data sets to see whether your information has already appeared in other incidents.
Continue to watch for official statements from ShapeCorp or relevant authorities. Until more verified detail is released, treat the nova listing as a claim rather than confirmed fact, and focus on the protective measures that remain under your control.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Shape Corp Listed by nova Ransomware GroupEpcatalogs Company Listed by nova Ransomware Grouphasbco Company Listed by nova Ransomware GroupTextile Testing Services of America Listed by nova Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ShapeCorp Listed by nova Ransomware Group →
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.