vpcgroup.com customfoam.com Listed by thegentlemen Ransomware Group: What Was Exposed & What To Do
Two sites operated by VPC Group, vpcgroup.com and customfoam.com, were listed by thegentlemen ransomware group on July 23, 2026, with internal files reported as exfiltrated; the date of the actual intrusion has not been established. Individuals who may have interacted with these domains are advised to monitor their accounts and consider any protective steps their information may require.
People who work with or buy from Custom Foam Systems may be wondering whether their personal or business details were caught up in a claimed ransomware incident. Public reporting so far is thin: the company appears on a leak site associated with the ransomware group thegentlemen, and the only concrete description available is that internal files were taken. The number of people affected remains unknown, so the practical risk for any individual cannot yet be measured with precision. Still, any organisation that holds customer, supplier or employee records creates real exposure when those records leave its control.
What follows sets out only what has been reported, places the claim in context, and outlines the steps ordinary people can take while fuller details are missing.
Breaking down the breach
On or about 23 July 2026, vpcgroup.com customfoam.com was listed by the ransomware group thegentlemen. The listing asserts that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of people whose information may be involved, or the precise date the intrusion began. The method of initial access, the duration of the attackers’ presence inside the network, and whether systems were also encrypted have not been disclosed in the material available. Because the sole source is a leak-site claim, independent confirmation of the breach itself has not been established in the public record.
In short, the known facts are limited to the group’s assertion that Custom Foam Systems was hit and that internal files left the organisation. Everything else—scale, timing beyond the report date, and exact contents—remains undisclosed.
Who is thegentlemen?
thegentlemen is a ransomware operation that has appeared in public reporting as a double-extortion group: it typically encrypts systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Like other groups of this type, it lists victim organisations by name and often posts sample files or directory listings to pressure payment. Its activity has been tracked across multiple sectors; the precise tooling and affiliates can change, but the core pattern—exfiltration followed by a public claim—is consistent with how the group presents itself.
For this incident the group claims that vpcgroup.com customfoam.com is a victim and that internal files were taken. No further statements attributed to thegentlemen about this specific organisation—such as ransom demands, deadlines or sample data—appear in the facts provided. The listing should therefore be treated as an unverified claim until corroborated by the company, regulators or independent forensic reporting.
vpcgroup.com customfoam.com and its sector
Custom Foam Systems (CFS), associated with the domains vpcgroup.com and customfoam.com, is a Canadian manufacturer of fabricated and molded custom polyurethane foam components. Founded in 1973 and based in Kitchener, Ontario, it supplies the automotive, healthcare and furniture industries across North America. The company states that it operates under ISO 9001:2015 and FDA-related standards and emphasises lean manufacturing and on-time delivery. As a long-established family-owned manufacturer serving regulated and safety-sensitive markets, it necessarily maintains relationships with original-equipment manufacturers, healthcare suppliers, distributors and its own workforce.
Manufacturers in this space routinely hold engineering drawings, material specifications, customer purchase orders, shipping and billing records, quality-control documentation and employee information. A breach at such a firm is consequential because the data can touch both commercial partners and individuals, and because healthcare-related supply chains often involve heightened expectations around data handling even when the manufacturer itself is not a direct healthcare provider.
The information in question
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No inventory of those files—whether they include customer lists, employee records, financial documents, technical drawings or other categories—has been published. The number of people affected is explicitly unknown.
Organisations of this kind typically store contact details for customers and suppliers, order and invoice history, product specifications, quality and compliance records, and human-resources data. It is reasonable to expect that some mixture of those categories could be present among internal files, yet it is not confirmed that any particular category was taken. Until the company or investigators release a clearer description, the exact contents remain unconfirmed.
What's at stake
For individuals, the concrete risks depend on what was actually in the files. If employee or contractor records were included, exposed names, addresses, government identifiers or bank details could enable identity theft or targeted phishing. If customer or supplier contacts appear, those parties may face business-email compromise attempts that reference real orders or shipments. Even purely technical or commercial documents can be used to craft convincing social-engineering messages.
For the organisation, the stakes include operational disruption if systems were encrypted, potential contractual or regulatory notification duties, and the longer-term erosion of trust with automotive, healthcare and furniture partners who rely on timely, confidential supply. Because the scale is undisclosed, neither the individual nor the corporate impact can yet be quantified; the prudent assumption is that anyone who has shared personal or business data with Custom Foam Systems should treat the possibility of exposure seriously until more is known.
Were you affected?
If you are a current or former employee, customer or supplier of Custom Foam Systems, monitor account statements and watch for unexpected emails or calls that reference the company. Change passwords on any accounts that reused credentials associated with the firm, and enable multi-factor authentication where it is available. Consider placing fraud alerts with credit bureaus if you believe sensitive personal identifiers may have been held. Official notification, if required, would normally come from the company itself; until that arrives, treat unsolicited messages claiming to be about “the breach” with caution.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can show whether your address is circulating more widely and help you prioritise further protections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
MatTek Listed by thegentlemen Ransomware GroupOptiforms Listed by thegentlemen Ransomware GroupHenry Frerk Sons Listed by thegentlemen Ransomware GroupDash Door Glass Listed by thegentlemen Ransomware GroupLatest breaches
Publicly posted by thegentlemen — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.