FR
live

AiLock claims Hamilton Company and threatens to report the breach to regulators

On August 26, 2026, the AiLock ransomware group added Hamilton Company, a US laboratory-robotics specialist, to its leak site, threatening to publish the data unless negotiations begin. The detail that sets AiLock apart: its double extortion threatens to report the breach to regulators and share stolen data with competitors — pressure that changes the victim’s calculus.

A dark metal safe with a single amber-lit dial, its door slightly ajar, resting on an anthracite workshop floor.

August 26, 2026. The AiLock ransomware group adds Hamilton Company to its leak site with an unambiguous ultimatum: “The full leak will be published soon, unless a company representative contacts us via the channels provided.” The target is no footnote: Hamilton Company (hamiltoncompany.com) builds liquid-handling and laboratory-robotics systems found in pharmaceutical and research labs. August 27, 2026. Ransomware trackers confirm the claim as AiLock keeps adding victims month after month.

The case deserves attention less for the victim than for the method. AiLock practices a double extortion that adds a novel threat: reporting the breach to regulators, and sharing stolen data with competitors.

Who is AiLock

AiLock is a Ransomware-as-a-Service (RaaS) operation, first identified in March 2025 according to RansomLook. The RaaS model means the malware is leased to affiliates who run the intrusions, while the group’s core runs the infrastructure, the encryption and the leak site. That division of labor explains the steady drumbeat of claims: 51 posts to date, 4 in the last thirty days and 2 in the last week, the most recent dated August 26, 2026.

The prior victim list draws an eclectic picture, with no favored sector: Sterling Industries (a contract manufacturer of medical devices), Raw Seafoods (a seafood processor), FUJIFILM Speciality Ink Systems (ink chemistry), Lewis Drug (a pharmacy chain), AJ Networks (equipment rental) and Integral Analytics (energy data intelligence). The scatter fits a RaaS model: affiliates strike where they find an open door, not according to a central plan.

Double extortion, the AiLock way

Double extortion is now ransomware’s default: encrypt the files and threaten to publish what was stolen. AiLock pushes it one step further. Per RansomLook, the group threatens to report the breach to regulators and to share stolen data with competitors if the ransom goes unpaid.

That refinement changes the victim’s economic calculus. A payment no longer buys silence; it merely avoids a double sanction — publication on the leak site on one side, and on the other a data-protection notification obligation, with its fines, triggered not by law but by the attacker itself. The “competitors” threat targets the strategic value of the data: for an equipment maker like Hamilton, handing plans or customer data to a rival can cost more than the encryption itself.

The timeline is tight: 72 hours to respond, up to 5 days to pay. Beyond that, the group promises both the data leak and the destruction of recovery tools — a message designed to stop the victim from betting on backups.

The technical detail that matters

On the purely technical side, AiLock stands out for its hybrid encryption scheme. Files are encrypted with ChaCha20, a fast stream cipher, while metadata is protected by NTRUEncrypt, a post-quantum algorithm based on lattice problems. The malware appends the .AiLock extension, swaps file icons for a green padlock and sets a robot-skull logo as the desktop wallpaper.

Two readings apply. The first is technical: ChaCha20 delivers fast bulk encryption, and NTRUEncrypt locks the session key in a way that even a future quantum computer would struggle to break — so victims cannot hope to recover files without the attacker’s key, now or later. The second is operational: the malware is multithreaded, with dedicated path-traversal and encryption threads (via IOCP completion ports), which speeds its crawl through the filesystem and shrinks the detection window.

Hamilton Company, a telling target

The choice of Hamilton Company is not neutral. The company makes pipetting robots and laboratory automation found in pharmaceutical research, biotech and hospitals. It is not classical OT — no production line to halt — but it is an OT-adjacent supplier: a compromise of its systems or data can propagate to healthcare customers whose tolerance for downtime is zero.

At this stage, nothing indicates Hamilton Company has confirmed the intrusion or the scope of the compromised data. The claim is, for now, unilateral — which is exactly how extortion works: the public threat is part of the pressure, before any negotiation even begins.

A wave, not an isolated incident

The claim against Hamilton Company does not arrive alone. On August 26 and 27, trackers logged a cluster of simultaneous publications: the Qilin group claimed the US federal ATF agency, and Aurora targeted the SAP integrator ERPIS, threatening to leak source code and financial databases. Three groups, three American victims, in the space of twenty-four hours.

That density is not an accident. Ransomware groups publish in waves, and each wave serves two purposes: saturating response teams and specialist media, and normalizing extortion as an everyday risk. For a CISO, the reading is inverted: a wave of publications is the moment when monitoring teams should raise their alert level, because the odds that a partner, supplier or customer appears on the next list go up mechanically.

What this changes for defense

Three lessons stand out beyond the specific case.

  • Regulatory notification becomes a weapon. When the attacker threatens to report the breach themselves, the question is no longer “should we notify” but “who notifies first”. Preparing the notification path in advance — DPO, competent authorities, affected customers — takes the lever out of the attacker’s hands.
  • Backups are no longer enough. AiLock promises to destroy recovery tools. Immutable, offline backups, tested for restore, remain the only credible countermeasure — not a network backup the malware can encrypt on its way through.
  • Segmentation matters as much as patching. An OT-adjacent supplier must isolate production systems from information systems and watch for lateral movement. Ransomware does not stop at the machine it encrypts.

Verdict

If you are a supplier to the healthcare or pharmaceutical sector, treat this claim as a signal about your own exposure: RaaS groups strike opportunistically, and your sector is a prime target. This week, verify that your backups are immutable and offline, and that your regulatory-notification path can start without notice.

If you are already negotiating with a ransomware group, internalize the novelty: the threat of reporting to regulators does not disappear with payment. Silence can no longer be bought — one more reason to favor restoration and proactive disclosure over paying.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

CVE-2026-59310 turns VMware vCenter into a Babuk ransomware launchpad

A path-traversal flaw in VMware vCenter, rated CVSS 9.8, allows unauthenticated code execution and is already being exploited across 47 countries to drop Babuk-derived ransomware. The fix is two moves: patch without waiting for a maintenance window, and cut the management interface off from the rest of the network.

A 2023 ownCloud flaw resurfaces and opens files with no credentials at all

CVE-2023-49105, a WebDAV authentication flaw rated CVSS 9.8 and fixed by ownCloud in late 2023, is now being actively exploited — CISA added it to the KEV catalog on 27 August 2026. Inventory your exposed ownCloud 10.x instances, move to 10.13.1 or later, and treat them as possible compromises.

← Back to the feed

Type at least two characters.

navigate open esc dismiss