Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible DistributionNOW (DNOW Inc.) data breach. According to dark web monitoring sources, a hacker group calling itself Falcon claimed responsibility for a cyberattack on DistributionNOW (DNOW Inc.) in a post first observed in August 2026, alleging it had gained access to internal company systems. As of this writing, DistributionNOW (DNOW Inc.) has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About DistributionNOW (DNOW Inc.)
DNOW Inc. (formerly DistributionNOW / NOW Inc.) is an energy and industrial solutions provider and a leading distributor of pipe, valves, fittings, pumps, and fabricated equipment. The company was spun off from National Oilwell Varco in 2014 and renamed DNOW Inc. in 2023. It serves upstream, midstream, downstream, gas utilities, energy transition, and industrial markets through a global network of approximately 145 distribution and engineering locations across the United States, Canada, and international markets, as well as digital commerce platforms. DNOW employs approximately 5,300 people and is publicly traded on the NYSE under the ticker DNOW, with its headquarters in Houston, Texas.
What Happened?
On August 30th, 2026, Ransomware.live reported that the Falcon ransomware group listed DistributionNOW (DNOW Inc.) as a victim on its dark-web leak site. Falcon is a newly emerged ransomware and data-extortion group first observed between April and August 2026, with only two indexed victims as of the date the claim appeared. Threat intelligence researchers at GuidePoint Security have linked Falcon-branded extortion activity to a broader adversary-in-the-middle phishing and vishing campaign tracked as UNC6671 (Google) and CORDIAL SPIDER (Okta), which has targeted energy, technology, financial services, and professional services organizations since at least April 2026. RedPacketSecurity has separately flagged that listings attributed to Falcon have been reported as including unverified or fabricated victim claims, and Ransomware.live itself warns that claims from this emerging group should be treated with caution until independently verified. No independent corroborating source confirming DNOW’s involvement was found.
In its dark-web post, Falcon alleged a 344 GB extraction and claimed the data includes corporate information, corporate bank statements, vendor payment instructions, payroll records, employee compensation data, tax documents, operational secrets, SCADA gateway backups, PLC logic programs, industrial automation project files, internal audit logs, whistleblower reports, employee disciplinary records, employee personally identifiable information, passports, driving licenses, and medical drug screen results. These are unverified attacker-side allegations only; DNOW has not confirmed or denied them. No ransom amount, payment demand, or publication deadline was stated in the leak-site post. Separately, DNOW is currently the subject of multiple securities class action lawsuits related to its acquisition of MRC Global Inc. and alleged ERP software integration failures, though that litigation is entirely unrelated to this ransomware claim.
Key Facts at a Glance
- Company or Organization: DistributionNOW (DNOW Inc.)
- Industry: Energy and industrial distribution
- Location: Houston, Texas (global operations)
- Incident type: Ransomware/data-extortion claim (unverified attacker allegation)
- Claim first observed: August 30th, 2026
- Litigation status: No litigation connected to this ransomware claim; separate securities class action lawsuits (unrelated to this incident) are pending with a lead plaintiff deadline of October 2nd, 2026
- Source: Ransomware.live – DistributionNOW (DNOW Inc.) · GuidePoint Security – Falcon-branded Extortion · RedPacketSecurity – Falcon Ransomware Victim: DistributionNOW · DNOW Inc. SEC Filing Form S-4
What Should You Do?
Because the incident has not been confirmed by DNOW, there is no enrollment in identity theft protection at this time. Regardless, if you are a current or former DNOW employee or a vendor or business contact whose information may be on file with the company, it is a good idea to place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—and to monitor your financial accounts and credit reports for unusual activity. You can request free annual credit reports at AnnualCreditReport.com. If your information is misused, report it at IdentityTheft.gov. Given the Falcon group’s unverified claim that the extracted data includes medical drug screen results, you may also wish to review any explanation of benefits statements or medical records you receive for services you did not authorize.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.