Flex Ltd Data Breach Investigation

Data Breach Blog

Data Breach

Flex Ltd Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

September 21, 2026

by: Almeida Law Group

Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Flex Ltd data breach. According to dark web monitoring sources, a hacker group calling itself metaencryptor claimed responsibility for a cyberattack on Flex Ltd in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, Flex Ltd has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.

About Flex Ltd

Flex Ltd (formerly Flextronics International Ltd.) is a publicly traded multinational electronics manufacturing services and original design manufacturer company (NASDAQ: FLEX). Legally domiciled in Singapore, the company maintains its U.S. operational headquarters in Austin, Texas. Flex provides design, engineering, manufacturing, supply chain management, and infrastructure solutions to customers across the automotive, healthcare, industrial, communications, data center, AI, and consumer technology sectors. The company operates more than 100 facilities in over 30 countries and employs approximately 148,000 to 150,000 people, with reported revenue of approximately $27.9 billion for the trailing twelve months ending March 2026.

What Happened?

On September 21st, 2026, ransomware tracking platform Ransomware.live reported that the MetaEncryptor ransomware group posted Flex Ltd (flex.com) on its dark-web leak site. This is an attacker-side allegation only. As of September 21st, 2026, Flex Ltd has not publicly confirmed or denied the claim, and no independent corroborating sources — such as regulatory filings, SEC disclosures, press statements, or journalist reporting — have verified the incident. No breach date, data volume, or specific data types have been identified by any source. The exact scope of any potentially exposed data remains unknown.

MetaEncryptor is a ransomware group first observed in mid-2023 that targets medium-to-large enterprises in legal, technology, logistics, manufacturing, and finance sectors, primarily in the UK, Europe, and Southeast Asia. The group uses AES-256/RSA-2048 encryption and a double-extortion model, encrypting systems and threatening to publish exfiltrated data. Security researchers have noted tactical overlaps with BlackCat (ALPHV), DarkVault, and MountLocker, and analysts believe the group is likely operated by a small, experienced team possibly based in Eastern Europe. MetaEncryptor claimed several other large organizations in September 2026, including AECOM, Beckman Coulter, EllisDon Corporation, and Promantra Inc. — none of which had publicly confirmed those claims at the time of reporting. As noted by security analysts, ransomware leak-site listings do not constitute independent verification that a breach occurred, and ransomware groups regularly mix genuine compromises with exaggerated or fabricated claims.

Key Facts at a Glance

What Should You Do?

Even though this incident has not been publicly confirmed, it is reasonable to take precautionary steps if you are a current or former employee, customer, or business partner of Flex Ltd. Consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your credit reports for unfamiliar activity at AnnualCreditReport.com. Review your financial accounts for any unauthorized transactions and remain alert to phishing attempts or suspicious communications that reference your personal information. If identity theft does occur, visit IdentityTheft.gov for step-by-step guidance on recovery.

Your Legal Rights

If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.