Cybersecurity

When Manufacturers Hit a Leak Site: Chaos Claims Against Glasfloss, Steelhaus & Peers

Chaos ransomware trackers listed Glasfloss, Steelhaus, and Artiflex Manufacturing mid-September—framed as leak-site claims without public company confirmation. Hygiene lessons for industrial SMBs and exhibit fab shops on CAD, ERP, employee records, and flat IT/OT networks.

When a manufacturer's domain appears on a ransomware leak site, production teams often hear about it from aggregators before any company statement lands. Mid-September 2026 tracker copy associated with the Chaos ransomware group listed multiple U.S. manufacturers, including Glasfloss Industries (glasfloss.com), Steelhaus (steelhausinc.com), and Artiflex Manufacturing (artiflexmfg.com, listed around Sept. 10). Aggregator pages on ransomware.live and related indexes described Glasfloss and Steelhaus claims discovered about Sept. 14, 2026, with actor-notice language citing large purported data volumes (on the order of ~402 GB corporate/financial/employee records for Glasfloss and ~152 GB for Steelhaus in aggregator copies of the notices).

Treat every line of that as an attacker claim / leak-site listing. In the sources used here, these companies have not publicly confirmed intrusion, payment, encryption, or what—if anything—was taken. Security Arsenal's Chaos multi-victim analysis (mentioning glasfloss, steelhausinc, artiflexmfg, and mankatoclinic among others) is useful for the pattern of manufacturing and healthcare targeting and for detection-rule discussion—not as forensic confirmation of intrusion chains at each named firm.

For industrial SMBs, HVAC/building-products manufacturers, energy-equipment makers, and exhibit / experiential fabrication shops in Rome and Northwest Georgia, the useful response is a hygiene drill aimed at CAD, ERP, employee records, and flat office/shop networks—not invented OT compromise stories.

What we know—and what we do not

Public tracker facts: Chaos-associated leak-site listings for Glasfloss / glasfloss.com and Steelhaus / steelhausinc.com around mid-September 2026; Artiflex Manufacturing / artiflexmfg.com listed around Sept. 10 in the same Chaos wave covered by Security Arsenal's four-victim analysis. Aggregator copies of actor notices claim multi-hundred-gigabyte data sets for Glasfloss and Steelhaus. We do not have company confirmations of compromise, verified inventories of stolen files, confirmed CAD/OT impact, or payment status. Leak-site cards are pressure tools; they are not incident reports.

That caution still leaves a real risk for production SMBs. After manufacturing leak-site headlines, phishing and "breach support" calls spike. Estimators get fake CAD-share links, controllers see spoofed ERP resets, and vendor remote-access accounts for nesting or materials software become attractive—whether or not your domain is on the card.

Why manufacturers and fab shops share a familiar attack surface

HVAC filter and building-products makers, energy-sector equipment shops, and exhibit-oriented fabrication houses often run denser stacks than leadership expects: CAD and nesting libraries, ERP and order entry, shared drives with customer drawings and BOMs, HR/payroll files, and remote access for vendors or traveling project managers. Flat networks between office identity and shop-floor PCs turn one phished mailbox into a path toward drawings and employee records alike.

Rome and Northwest Georgia production shops do not need a Glasfloss or Steelhaus ZIP code to share that pattern. The right question is: If Chaos put our domain on a card tomorrow, which MFA, segmentation, and restore controls would already be enforced?

Clear takeaway

Frame every manufacturing leak-site claim as a drill until the company confirms—and harden MFA, office/shop segmentation, vendor remote access, immutable CAD/ERP/HR backups, and post-headline phishing readiness either way. Treat drawings, order systems, and employee records as crown jewels, not side projects.

Actions to take this week

  1. Require MFA on email, ERP, VPN/RDP, CAD portals, HR/payroll, and vendor support logins. No shared "shop office" passwords that skip second factors.
  2. Segment shop-floor / OT networks from office file servers and CAD libraries. Production machines should not hold the full customer-drawing or HR share "for convenience."
  3. Inventory and expire vendor remote-access accounts. CNC, materials, and freelance estimators need time-boxed access—not standing passwords.
  4. Protect CAD, ERP, and employee-record archives with least privilege and offsite immutable backups. Test a restore of active jobs and a sample HR export before a rush week.
  5. Brief estimators, controllers, and shop leads on post-headline phishing. Unexpected "leak remediation," gift-card, or CAD-share links after a Chaos manufacturing story are part of the attack surface.

Brotherly Technology works with manufacturers, building-products suppliers, energy-equipment makers, and exhibit / experiential fabrication shops across Northwest Georgia to harden the identity and restore paths that keep production moving—without inventing confirmation a company has not issued. Chaos's claimed Glasfloss, Steelhaus, and peer listings are a timely reminder to run that drill for industrial SMBs now.

Sources:

  • ransomware.live / related aggregator pages for glasfloss.com and steelhausinc.com — Chaos listings discovered ~Sept. 14, 2026; aggregator copies of actor notices citing purported ~402 GB (Glasfloss) and ~152 GB (Steelhaus) data. Treat as leak-site / attacker claims; company confirmation of intrusion/scope not in sources used here.
  • Security Arsenal — Chaos 4-victim analysis — mentions glasfloss, steelhausinc, artiflexmfg, mankatoclinic; useful for manufacturing/healthcare targeting pattern and detection discussion; not confirmation of intrusion chains at each firm.
  • GalaxyWarden / DeXpose-style aggregator framing for Glasfloss claim (claim-level only; not company confirmation).

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation