Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible SIFCO Industries INC. data breach. According to dark web monitoring sources, a hacker group calling itself metaencryptor claimed responsibility for a cyberattack on SIFCO Industries INC. in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, SIFCO Industries INC. has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About SIFCO Industries INC.
SIFCO Industries, Inc. is a publicly traded global manufacturer of forgings and machined components, trading on AMEX under the ticker symbol SIF. Founded in 1913 and headquartered in Cleveland, Ohio, the company serves the aerospace, energy, defense, and commercial space markets. Its products include OEM and aftermarket components for aircraft and industrial gas turbine engines, structural airframe components, aircraft landing gear, wheels and brakes, and helicopter rotating parts. The company reported approximately $100 million in annual revenue and employed roughly 378 people as of 2021.
What Happened?
SIFCO Industries INC. was listed in a ransomware leak-site allegation reported by Ransomware.live. The claim, attributed to the ransomware group metaencryptor, was first observed on September 7th, 2026. No public confirmation from SIFCO Industries, SEC filings, press releases, or independent news coverage corroborating this specific 2026 claim has been found. The description posted by metaencryptor on its dark-web leak site appears to have been copied from SIFCO’s own marketing materials rather than describing specific stolen data. No specific data types have been identified as compromised in this alleged incident.
SIFCO Industries has a documented history of being targeted by cyber attackers. In late December 2022, the company disclosed an unauthorized access incident in which a threat actor gained access to its systems on or about December 27th, 2022, with the company becoming aware of the intrusion on December 30th, 2022. That incident impacted domestic operations, caused production and shipment delays, and resulted in SIFCO notifying affected individuals consistent with state and federal requirements. SIFCO recorded approximately $3.1 million in costs related to that attack and received $3 million in cybersecurity insurance proceeds on February 20th, 2023. The current 2026 allegation by metaencryptor should be treated as an unverified claim pending any official disclosure. MetaEncryptor is a double-extortion ransomware group active since approximately early 2022 that encrypts systems and threatens to publish exfiltrated data. Security researchers have linked metaencryptor to the later LostTrust ransomware operation, which is suspected to be a rebrand with nearly identical leak sites and Windows encryptors. Ransomware.live lists approximately 31 known metaencryptor victims across manufacturing, legal, technology, logistics, and finance sectors.
Key Facts at a Glance
- Company or Organization: SIFCO Industries INC.
- Industry: Manufacturing — Aerospace & Defense / Energy forgings and machined components
- Location: Cleveland, Ohio, United States
- Incident type: Ransomware leak-site allegation (dark-web claim, unverified)
- Prior breach: Confirmed unauthorized access incident disclosed December 30th, 2022
- Litigation status: No litigation connected to this September 2026 alleged incident has been reported
- Source: Ransomware.live — metaencryptor claim · SIFCO Industries — Cyber Incident Customer Communication · SEC 10-Q Filing — December 2022 Cyber Incident · SOC Prime — LostTrust / MetaEncryptor Connection · WatchGuard — MetaEncryptor Ransomware Tracker
What Should You Do?
Although the specific data involved in this alleged incident has not been confirmed, it is always a good idea to take protective steps when your information may be at risk. You can place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to make it harder for someone to open accounts in your name. Review your credit reports for free at AnnualCreditReport.com and watch for unfamiliar accounts or charges. Monitor your existing financial accounts closely for any suspicious activity. If identity theft does occur, you can report it and get a personal recovery plan at IdentityTheft.gov.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.