Cybersecurity

When the Fabrication Shop Is the Target: Akira’s Early-September Metals Hits

Akira listed Congressional Iron Works (~Sept. 1) and PennFab (~Sept. 2) with actor claims about corporate data, employee PII, clients, and NDAs—still leak-site claims pending org disclosure. Lessons for exhibit houses, experiential fab shops, and metals SMBs on shop-floor + office IT.

Early September 2026 put two metals and structural-steel fabricators on the same ransomware crew’s scoreboard within about a day of each other. Aggregators indexed Akira listings for Congressional Iron Works around September 1, 2026 and PennFab around September 2, 2026 (coverage carried by ransomware.live and cyberthreatintelligence.net-style indexes). Both remain actor-side claims until the organizations speak for themselves—Breach House still showed disclosure / notification as pending for Congressional Iron Works in mid-September checks we reviewed.

That pairing matters for exhibit houses, experiential fabrication shops, and industrial metals SMBs in markets like Rome and Northwest Georgia. The data shape is familiar even when the product mix differs: estimating and drafting files, project folders, NDAs, client contacts, and office systems that sit too close to the shop floor.

What the actor claims say—carefully attributed

For Congressional Iron Works (Baltimore–Washington miscellaneous metals / fabrication spanning estimating, drafting, fab, and project management), public claim text carried by trackers alleges roughly 35GB of corporate data “soon,” including employee PII such as passports, SSNs, driver’s licenses, and financial/health information, plus clients, financials, projects, and NDAs. That is the attacker’s narrative—not a verified inventory.

For PennFab (Pennsylvania structural steel fabrication—engineering, welding, custom metal fab), claim text similarly alleges roughly 40GB “soon,” including employee PII for about 53 employees, clients, contacts/agreements, financials, and NDAs, per aggregator writeups. Again: attribute as a claim. Do not treat volumes or employee counts as confirmed forensic findings.

Why fabrication shops are a high-value target shape

Shop-floor PCs, CAD/drafting workstations, shared project drives, and vendor remote access for estimating plugins or CNC support often share flatter networks than leadership expects. One compromised mailbox or an always-on VPN/RDP path can reach bid packages, as-built drawings, and client NDAs in the same haul criminals advertise on leak sites.

Exhibit and experiential fabricators feel the same pressure from a different angle: show deadlines, client brand kits, and installer accounts. Metals shops feel it through bid confidentiality and employee PII. The control list overlaps: segment office from OT/shop networks, MFA everywhere, constrain vendor remote access, and keep immutable backups of CAD and project files—not only the file server that “usually” restores.

Clear takeaway

When fabrication shops are the target, CAD, project files, and employee/client PII are the ransom—not only locked shop PCs. Segment shop-floor and office IT, enforce MFA on VPN/RDP and Microsoft 365, lock down vendor remote access, and keep offsite immutable backups you have actually restored.

Actions to take this week

  1. Segment shop-floor / OT networks from office file servers and CAD libraries. Production machines should not hold the full client and HR share “for convenience.”
  2. Require MFA on Microsoft 365, VPN, RDP, and estimating/vendor portals. Phishing into drafting email remains a common path into project folders.
  3. Inventory and expire vendor remote-access accounts. CNC, software support, and freelance estimators should get time-boxed access—not standing passwords.
  4. Protect CAD and project archives with least privilege and offsite immutable backups. Test a restore of active jobs and archived bids before a deadline week.
  5. Treat employee PII like production IP. HR folders and scanned IDs belong in tightly controlled shares, not on every estimator’s desktop.

Brotherly Technology works with manufacturers, fabricators, and exhibit-oriented production shops across Northwest Georgia to harden the files that win bids and keep crews paid—without waiting for a leak-site card with your domain on it. Akira’s early-September metals listings are a clear signal: assume criminals want your drawings, your NDAs, and your people data, and build controls that make that haul hard to grab.

Sources:

  • ransomware.live — Akira victim indexing for Congressional Iron Works (~Sept. 1, 2026) and PennFab (~Sept. 2, 2026)
  • cyberthreatintelligence.net and related aggregators — claim text summaries attributing ~35GB / employee-client-financial-NDA allegations (Congressional Iron Works) and ~40GB / ~53-employee PII plus clients-agreements-financials-NDAs (PennFab). Actor claims only.
  • Breach House — Congressional Iron Works disclosed/notified pending as of mid-September 2026 checks reviewed for this article

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation