Were you recently affected by a data breach?

Cleaver-Brooks Data Breach

Cleaver-Brooks, a leading industrial boiler manufacturer based in Thomasville, Georgia, was reportedly listed on a dark web leak site by the ransomware group Anubis in August 2026. The company has not yet confirmed the incident or disclosed what personal information may have been exposed.

Cleaver-Brooks
Date of Breach: August 10, 2026 (reported)
CAU logo

Who was affected:

Clients of Cleaver-Brooks

Impacted Data:

Not yet publicly disclosed

Cleaver-Brooks, a Thomasville, Georgia-based manufacturer of industrial boilers and boiler room equipment, was reportedly named on a dark web leak site by a cybercriminal group known as Anubis in August 2026. The group claimed to have obtained company data, though Cleaver-Brooks has not publicly confirmed the incident and the specific categories of information involved have not been disclosed.

Companies that manufacture industrial equipment often maintain large amounts of sensitive data about their employees, customers, and business partners, and they have a legal and ethical responsibility to keep that information secure.

Cleaver-Brooks’s Data Breach Investigation

According to a dark web posting monitored by cybersecurity researchers, the ransomware group Anubis claimed responsibility for a cybersecurity incident involving Cleaver-Brooks. The claim was reportedly posted to a leak site in early-to-mid August 2026, with the underlying intrusion said to have occurred around August 10, 2026. As of this writing, Cleaver-Brooks has not issued a public statement confirming the incident, and the group behind the leak site posting did not disclose specific details about the volume or type of data it claims to have taken.

Ransomware groups like Anubis typically operate by infiltrating a company’s network, exfiltrating files before deploying encryption malware, and then threatening to publish stolen data on a leak site unless a ransom is paid. This extortion model means that even if a company avoids paying a ransom, previously stolen data can still end up exposed or sold to other bad actors. Manufacturing companies have increasingly become attractive targets for these groups because industrial firms often manage large employee and vendor databases while sometimes running older operational technology systems that can be harder to patch and secure than typical office networks.

Because Cleaver-Brooks has not yet confirmed which categories of personal information, if any, were accessed, it remains unclear whether the incident involved employee records, customer or vendor data, financial account information, or some combination of sensitive data types. Investigations into ransomware-related dark web postings like this one often take weeks or months to fully resolve, as companies work with forensic investigators to determine the scope of what was actually accessed before issuing formal notifications to anyone who may be affected.

In the meantime, individuals connected to Cleaver-Brooks as employees, former employees, customers, or business partners may want to stay alert for any official communication from the company and monitor their accounts for unusual activity, since dark web leak site claims sometimes precede a formal breach notification by a significant amount of time.

When Did This Breach Occur?

The Anubis group’s dark web posting referencing Cleaver-Brooks was tracked by cybersecurity monitoring services around August 10-11, 2026. Cleaver-Brooks has not publicly confirmed an exact date of intrusion or disclosed when the incident was first detected internally, so the full timeline — including when any unauthorized access may have begun and when the company itself became aware of it — is not yet publicly available.

What Information Was Breached?

The categories of information potentially involved in this incident have not been publicly disclosed. The Anubis group’s leak site posting did not specify what types of data, if any, were taken, and Cleaver-Brooks has not issued its own statement identifying affected data categories. Until the company or investigators release additional details, the specific personal information at risk — whether related to employees, customers, or business partners — remains unconfirmed.

What You Can Do

If you believe you may have a connection to Cleaver-Brooks as an employee, former employee, customer, or vendor, consider taking the following steps:

  • Monitor your financial accounts and credit reports for any unauthorized or suspicious activity
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus
  • Be cautious of phishing emails, texts, or phone calls referencing Cleaver-Brooks or this incident
  • Use unique, strong passwords for your accounts and enable two-factor authentication where available
  • Keep any official notice you may receive from Cleaver-Brooks about this incident for your records

File a Data Breach Lawsuit Against Cleaver-Brooks

If Cleaver-Brooks confirms that your personal information was compromised in this incident, you may have legal options. Companies that collect and store sensitive personal data are generally required to implement reasonable safeguards to protect that information, and a failure to do so can potentially form the basis of legal claims on behalf of those affected.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 10, 2026 (reported)
Date of Breach: January 19, 2026 - April 14, 2026
Date of Breach: March 24, 2026 - March 30, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.