~/cyphlet $ grep -r "Ransomware: lockbit5 named pscindustries.com (US)" ./investigations/ --include="*.md"
Ransomeware

Ransomware: lockbit5 named pscindustries.com (US)

Cyphlet05 Sep 20263 min read

1. Executive summary

On 4 September 2026, the ransomware operator tracked as “lockbit5” publicly listed PSC Industries (pscindustries.com), a US industrial supplier of insulation, gasketing, seals and adhesives, as a victim on its leak site. The listing is a claim of compromise and typically signals that the operator asserts possession of stolen data, with implicit or explicit extortion leverage. No technical detail on initial access, malware, or exfiltrated content is available in the source material; the claim is single-sourced (ransomware.live’s monitoring of the group’s leak site) and the actor “lockbit5” has no MITRE ATT&CK profile in our verified reference data, so attribution must be treated as unconfirmed. Direct risk to EMEA financial services is low: PSC Industries is an industrial manufacturer, not a financial entity or a known ICT service provider to the sector. The advisory value is situational — leak-site listings of this type are occasionally fabricated or recycled by rebranded groups, and clients should not treat the claim as confirmed intrusion evidence.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is a third-party leak-site claim against a US industrial manufacturer with no demonstrated connection to EMEA financial services entities, their ICT third-party providers, or their supply chains. A generic “a third party was victimised” trigger would apply to virtually any ransomware listing and does not meet the threshold for engagement.

3. Technical analysis & attack chain

No confirmed attack chain can be reconstructed from the source material. The ransomware.live entry contains only the group name (“lockbit5”), the victim domain (pscindustries.com), the victim country (US), and a truncated company description (“For over 60 years, PSC Industries has been the number 1 supplier of nsulation, gasketing, seals, adh…”). No initial access vector, exploited CVE, malware family, payload, persistence mechanism, C2 infrastructure, exfiltration evidence, or ransom note content is provided.

Single-sourced and unconfirmed claims — treat with caution

  • The compromise claim itself is single-sourced: it rests entirely on ransomware.live’s indexing of the lockbit5 leak site. No second source corroborates the intrusion, and no independent confirmation (victim statement, regulatory filing, technical telemetry) is present in the material.
  • Attribution to “lockbit5” is unconfirmed. The actor has no MITRE ATT&CK profile in our verified reference data. The name suggests a relationship to the historical LockBit operation (disrupted by law enforcement in February 2024), but no evidence in the source material establishes continuity, rebranding, or affiliation — do not assume it.
  • The external source notes DNS records exist for the victim domain but does not enumerate them; no infrastructure overlap between the victim domain and attacker infrastructure can be assessed.
  • Ransomware.live explicitly does not access or verify the underlying stolen data; the listing confirms only that the claim was posted, not that data was actually stolen.

What the listing format implies (inference, clearly flagged): leak-site victim listings of this kind conventionally precede or accompany a data-extortion demand, where the operator claims exfiltrated data and threatens publication if payment is not made. Whether encryption occurred at the victim, whether data was actually exfiltrated, and the volume or sensitivity of any such data are all unknown from this material. We do not characterise this as confirmed ransomware deployment — only as a claimed victim listing.

4. Mitigation & containment

No victim-side containment is actionable from this material — the advisory concerns a third-party claim, not a compromise of client infrastructure. Prioritised actions are exposure-management and third-party checks:

P1 — within 24h

  • Check whether PSC Industries (pscindustries.com) appears in your vendor master, supplier register, or third-party ICT provider inventory. If there is a commercial relationship, escalate to your third-party risk function for direct confirmation of the incident and assessment of any data shared with the victim (design documents, purchase orders, payment details, personnel data).
  • Hunt your email gateway, proxy, and DLP logs for traffic to/from pscindustries.com over the past 90 days to establish whether any of your data or credentials transited to the victim environment.
C
Cyphlet