The leak claims about 118 GB of Ingersoll Rand data from the IRCO software/hardware ecosystem were taken, including software/firmware packages, controller firmware, eMMC/Linux images, Windows installers, fieldbus configuration files, tooling, and deployment materials. The group states the data is published on their leak site and shows a countdown for additional data release, with the post marked as published. The victim is Ingersoll Rand (IRCO, irco.com); the note claims access to equipment used on automotive assembly lines and references major automakers such as Volkswagen, BMW, General Motors, Nissan, and Ford, noting potential impact on automotive and defense customers.
Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.
Ransomware leak page for Ingersoll Rand; claims access to IRCO archive including INSIGHTqc/INSIGHTqcx/QX/QE/QM/ICS packages, controller firmware, eMMC/Linux images, Windows installers, fieldbus configuration files, Hilscher/SYCONnet/netX tooling, and deployment materials; notes 118 GB of data in the IRCO archive; mentions impact on automotive and defense customers.
Published by the group on their leak site, reproduced verbatim.
Six months ago we warned the company We are in possession of a complete archive of your software and hardware ecosystem: INSIGHTqc, INSIGHTqcx, QX/QE/QM/ICS packages, controller firmware, eMMC/Linux images, Windows installers, fieldbus configuration files, Hilscher/SYCONnet/netX tooling, and all associated deployment materials. We had direct access to your internal configuration management systems and, over a defined period, made changes to equipment settings that are deployed on the production lines of major automotive manufacturers and in the aerospace industry. 1. Your equipment is used on the assembly lines of key automotive industry players. Volkswagen: Ingersoll Rand is a Preferred Partner, with equipment installed at the Chattanooga, Tennessee plant. BMW: Centac C400 compressors supplied to BMW's production line. General Motors: Supplier Quality Excellence Award recipient for 4 consecutive years. Nissan: direct technical integration via the Nissan EOR Out protocol in INSIGHTqc. Ford: directly confirmed in the Global Supplier Quality Manual. 2. The scale of your presence in the automotive industry extends beyond the brands listed above. Your solutions are used in the supply chain for battery production by companies including Tesla, Nissan, and Jaguar. This means your equipment is embedded in critical nodes of the supply chains for the entire electric vehicle sector. 3. Your business has deep ties to the U.S. defense sector. Ingersoll Rand is an official supplier to the U.S. Department of Defense. You have active contracts with critical military infrastructure facilities. U.S. Army: In April 2026, a tender was announced for the supply and installation of your compressor system for Rock Island Arsenal, Joint Manufacturing and Technology Center, a key U.S. Army production complex. U.S. Navy: In May 2026, a tender was announced for the procurement of your compressor for USNS Henry J. Kaiser, a U.S. Navy vessel. U.S. Air Force: In July 2026, a tender was issued for the procurement of two of your compressors for aircraft maintenance at Altus AFB. 4. Your equipment also serves the global aerospace industry. The QX Series is used for assembling fuselages, wings, and landing gear of aircraft. Any compromised settings pose direct risks to the quality of aircraft assembly. In the automotive industry, an error in torque settings can result in the recall of hundreds of thousands of vehicles. In the last two years alone, recalls due to improper bolt tightening have been announced by Ford: 180,000 Bronco and Ranger (seat bolts). Honda: more than 46,000 Civic units in the UK and more than 406,000 Civic units in the US, as well as thousands of Passport and Pilot units. Volvo: XC60. Kia: EV9 (25,000 vehicles). Mazda: CX-50. Porsche: thousands of sports cars. VW: Tiguan, Atlas, ID.4. BMW: X5, Rolls-Royce Cullinan. In aviation, the cost of error is even higher: it involves the lives of hundreds of people and a reputational catastrophe comparable to the Boeing 737 MAX crisis. Automaker Responses to Quality Issues: Ford, in May 2026, announced a policy of public exposure and no bid lists for suppliers with quality problems. Suppliers with quality issues are barred from bidding on new contracts, publicly named, and can be replaced. Volkswagen requires suppliers to have a certified cybersecurity management system and strict compliance with Formel Q Konkret. BMW requires immediate error notification and applies escalation measures up to and including contract termination. General Motors requires compliance with IATF 16949 and PPAP. If automakers or aviation regulators (FAA, EASA) learn that your equipment configurations could have been compromised, they will not investigate the details. They will apply their stringent measures. For Ingersoll Rand, this means loss of Preferred Partner status with Volkswagen, loss of contracts with Ford, BMW, GM, Nissan, public exposure by Ford, multi-billion-dollar collective lawsuits from automakers, investigation by the FAA and EASA, loss of defense contracts with the U.S. Department of Defense, and reputational catastrophe in the aerospace industry. 9,405 9,405 views Aug 17 DataBase Leaked https://fex.net/s/f61fepb 9,408 9,408 views Aug 17 The files will be published after the timer counts down. The company still has time to get in touch with us https://fex.net/s/f61fepb 12,297 12,297 views Jul 22 irco.com 118 GB Database The IRCO archive contains 118 GB of data. The data is organized around industrial tooling software, embedded controller packages, product releases, firmware, Windows installers, USB and eMMC deployment images, industrial communication files, fieldbus tools, driver packages, customer/demo builds, manuals, support utilities, engineering files and development/project materials. 1. Product and Release Coverage The archive contains several product and release families: - INSIGHTqc releases; - INSIGHTqcx releases; - InsightQCD Multi releases; - InsightQCX MTC releases; - InsightQCX2000 MTC releases; - QX Series packages; - QE / QM / QX Series ICS USB packages; - ICDM controller software packages; - IC-PCM software packages; - MCE packages; - QX Display firmware; - QX Wireless firmware; - INSIGHT Connect application packages; - WiFi application packages; - EOR Export and tightening-data utilities; - fieldbus and industrial-network configuration packages; - INSIGHTqc QC Profinet production package. 4. INSIGHTqcx Releases The INSIGHTqcx release branch contains versioned application packages and USB deployment packages. The archive contains: - Version 1.0.1; - Version 1.0.5; - Version 1.1.6; - Version 1.2.2; - Version 2.0.0; - Version 2.0.1; - Version 2.0.7; - Version 2.0.10; - Version 2.0.13; - Version 2.0.19; - Version 2.0.27; - Version 2.0.37. INSIGHTqcx Version 2.0.19 contains commercial release notes, application package 2_0_19_package.irb, USB deployment files, emmcimage.tar.bz2, blast.sh, env.txt, tsinit, tsinit.ub, device-tree files, initramfs, ts4900-fpga.bin and zImage. The newer INSIGHTqcx branch includes Version 2.0.27 with release notes and 2_0_27_package.irb, and Version 2.0.37 with an application package. 5. Production Releases The production release area contains QEQM-QX / ICS USB packages. Production packages include: - QEQM-QX Series ICS USB Package 1.2.0; - QEQM-QX Series ICS USB Package 1.4.15; - QEQM-QX Series ICS USB Package 1.4.20; - QEQM-QX Series USB Package 1.4.10. QEQM-QX Series ICS USB Package 1.2.0 contains: - ICSInstaller.exe; - VersionInfo.txt; - EOR Data Acquisition.xls; - Tightening Curve Acquisition.xls; - IC-PCM software; - qx_risc.irb; - ICDM Controller Software; - icdm_runtime.irb; - ICDM-MCE Software; - icdm_mce.irb; - TI MCE package; - icdm_mce_ti.irb; - ICS Help File; - ICS license file; - Label Printing Software. QEQM-QX Series ICS USB Package 1.4.15 contains: - ICSInstaller.exe; - EOR Export.exe; - EOR Data Acqui
Fields this group publishes that do not map to a standard column. Labels are the site's own.
Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.