A group of hackers calling themselves “The Dark Overlord” have claimed to have stolen confidential data from a major US critical infrastructure manufacturer. The data, which is said to include blueprints, schematics, and other sensitive information, could be used to attack or sabotage the company’s operations.
The hackers have reportedly put the data up for sale on a dark web forum. They are asking for $2,000 in Bitcoin for the data. The company that was hacked has not been identified, but it is believed to be one of the following:
- General Electric
- Siemens
- Schneider Electric
- Eaton
- ABB
These companies are all major manufacturers of equipment used in critical infrastructure, such as power plants, water treatment facilities, and transportation systems. If one of these companies were to be hacked, it could significantly impact the country’s critical infrastructure.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the AI risk, regulation, abuse, and enterprise security changes this article could not cover.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The hackers have released a sample of the data they claim to have stolen. The sample includes blueprints for a power plant and schematics for a water treatment facility. The hackers also claim to have stolen company employees’ data, including their names, addresses, and Social Security numbers.
The company that was hacked has not commented on the incident. The FBI is investigating the matter.
The Dark Overlord is a well-known hacking group. They have been responsible for some high-profile cyberattacks, including the theft of data from the US Department of Justice and the US Department of Homeland Security.
The group’s motives are unclear. They have claimed to be motivated by a desire to expose government corruption and to bring about social change. However, some experts believe that the group is motivated by financial gain.
The theft of confidential data from a critical infrastructure manufacturer is a serious threat. If the data falls into the wrong hands, it could be used to plan and carry out attacks on the company’s facilities or on other critical infrastructure targets.
This incident is a reminder of the importance of cybersecurity for critical infrastructure companies. These companies need to take steps to protect their data from cyberattacks. They must implement strong security measures like firewalls, intrusion detection systems, and data encryption. They also need to train their employees on cybersecurity best practices.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The government also has a role in protecting critical infrastructure from cyberattacks. The government needs to invest in cybersecurity research and development. It must also work with critical infrastructure companies to develop and implement security standards.
The theft of confidential data from a critical infrastructure manufacturer is a serious threat. It is important for companies and governments to take steps to protect critical infrastructure from cyberattacks.
Here are some additional tips for protecting your organization from cyberattacks:
- Use strong passwords and change them regularly.
- Keep your software up to date.
- Be careful about what information you share online.
- Use a firewall and antivirus software.
- Back up your data regularly.
- Train your employees on cybersecurity best practices.
By following these tips, you can help to protect your organization from cyberattacks.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 18, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.