steelerubber.com Listed by cactus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
steelerubber.com has been listed by the Cactus ransomware group, with internal files reported to have been exfiltrated in the attack; the incident came to light on February 05, 2025, though the date the breach occurred has not been established. Individuals are advised to check whether their information may have been exposed and take appropriate protective steps.
On February 05, 2025, steelerubber.com was listed by the cactus ransomware group as a victim of a ransomware attack in which internal files were allegedly exfiltrated. Public reporting provides no confirmed figure for the number of people affected, and further operational details remain limited. The listing itself is a claim by the group rather than an independently verified confirmation of the full scope of the incident.
For an organisation that manufactures specialised rubber and weatherstrip components used in classic vehicles, any exposure of internal files raises practical questions about what business records, customer details or operational data may have been involved. At this stage, the precise contents and scale of the material remain unconfirmed beyond the group’s assertion of exfiltration.
Inside the incident
Public information states that steelerubber.com was listed by the cactus ransomware group on or around February 05, 2025. The available summary describes the event as a ransomware attack in which internal files were allegedly exfiltrated. No technical details of the initial access method, encryption timeline, ransom demand or negotiation have been disclosed in the material provided. The number of people affected is listed as unknown, and no volume of data, file counts or specific document categories beyond “internal files” have been made public. The group’s leak-site listing constitutes its claim that the organisation was compromised and that data was taken; independent verification of those claims is not contained in the reported facts.
Who is cactus?
Cactus is a ransomware operation that has been active in recent years and is known for employing double-extortion tactics. In documented cases the group typically gains access to a network, exfiltrates data, encrypts systems, and then pressures victims by threatening to publish the stolen material on a dedicated leak site if payment is not made. Public reporting on cactus has described the use of custom tools, living-off-the-land techniques and careful targeting of mid-sized organisations across multiple sectors. The group’s listings are claims of compromise; they do not by themselves constitute forensic confirmation of every detail asserted about a particular victim. In the present case, the only claim attributed to cactus regarding steelerubber.com is the listing itself and the assertion that internal files were exfiltrated.
Who is steelerubber.com?
Steele Rubber Products, operating as steelerubber.com, is a United States manufacturer of automotive weatherstrip and rubber parts designed for classic cars, trucks and hot rods. According to publicly available descriptive material, the company has supplied windshield, door, window, hood and trunk seals as well as gaskets, pedal pads, fuel-system components and related hard-to-find parts since the mid-1960s. It is located at 6180 Hwy 150 E, Denver, North Carolina, and is reported to generate approximately $17.9 million in revenue. Organisations of this type typically maintain customer order histories, shipping and billing records, supplier contracts, product specifications, employee information and internal operational documents. A ransomware incident affecting such a manufacturer can therefore touch both commercial continuity and the personal or business data of customers and partners who rely on the firm for specialised restoration parts.
The information in question
The only data category named in the available facts is “internal files exfiltrated in ransomware attack.” No further breakdown—such as customer databases, financial records, employee files, intellectual property or email archives—has been disclosed. Because the precise contents remain unconfirmed, it is not possible to state with certainty which specific records were taken. Companies in the automotive-parts manufacturing sector commonly hold order and shipping data, payment details, contact information for dealers and individual restorers, engineering drawings, inventory systems and internal correspondence. Whether any of those categories were among the exfiltrated material in this incident is not established by the public record.
Why it matters
For individuals or businesses that have ordered parts from Steele Rubber Products, the practical risk centres on the possible exposure of contact, address or payment-related information that could be used for phishing, social-engineering attempts or identity-related fraud. Even when the exact data set is unknown, the mere assertion that internal files left the organisation creates a period of uncertainty during which affected parties may receive unsolicited communications that appear legitimate. For the company itself, a ransomware event can disrupt production, shipping and customer service, and can impose recovery costs, legal notification obligations and reputational pressure. Because the number of people affected is listed as unknown and the file contents are not detailed, the full extent of those risks cannot yet be quantified from public sources alone.
Were you affected?
If you have done business with steelerubber.com, monitor financial statements and email accounts for unexpected activity, and treat any unsolicited messages that reference the company or past orders with caution. Consider changing passwords on accounts that may have reused credentials associated with the firm, and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official notifications, if any are issued by the company or by regulators, will provide the most authoritative guidance on next steps specific to this incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
lifting.com Listed by cactus Ransomware Groupchfindustries.com Listed by cactus Ransomware GroupThis entry has been removed following a request from the company. Listed by cactus Ransomware Groupthermoid.com Listed by cactus Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the steelerubber.com Listed by cactus Ransomware Group →
Publicly posted by cactus — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.