American Casting Company Data Breach Exposes Sensitive Corporate and Employee Information

Published: 18 September 2026
Manufacturing data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

American Casting Company, a California aerospace and medical parts foundry, suffered a ransomware attack claimed by the Storm group, with notification occurring in September 2026. The breach may have exposed employee and business data. Affected individuals should monitor credit reports, consider a credit freeze, and watch for phishing attempts immediately.

CompanyAmerican Casting Company
IndustryManufacturing
Data Types ExposedEmployee Personal Information, Human Resources Records, Internal Business Documents, Client or Vendor Contact Information, Proprietary Manufacturing Data
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the American Casting Company Data Breach?

American Casting Company, an investment casting foundry based in Hollister, California, has confirmed it was targeted in a ransomware attack. The company serves aerospace, medical, defense, and industrial clients. As a result, the incident raises concerns beyond the business itself, touching partners and employees connected to its operations.

A threat actor group known as Storm has claimed responsibility for the attack. Ransomware groups like Storm typically infiltrate networks, steal files, and then threaten to publish or sell that data. The breach discovery date has not been publicly disclosed. However, the notification to affected parties occurred in September 2026.

Because the company holds NADCAP and AS9100 certifications, it manages sensitive supply-chain and manufacturing data. Following discovery of the intrusion, American Casting Company likely engaged cybersecurity specialists to assess the scope of the breach. This kind of forensic investigation typically aims to determine which systems were accessed and what data the attackers copied before any files were locked or leaked.

At this time, full technical details of the attack chain remain limited. Still, the claim by the Storm group indicates that data theft, not just system disruption, was involved. This distinction matters because it confirms that personal and business information may have left the company’s network.

Who was affected?

The exact number of individuals affected by this breach has not been publicly disclosed. Given that American Casting Company employs between 51 and 200 people, the pool of potentially affected individuals likely includes current and former employees. In addition, business partners, vendors, and possibly clients in the aerospace and medical sectors could be impacted.

Because the company works with defense and medical industry clients, there is a possibility that sensitive business records tied to those relationships were also exposed. This could extend the breach’s reach beyond direct employees to third-party organizations that share data with American Casting Company.

At this stage, it remains unclear whether the exposed information belongs primarily to employees, customers, or both. Anyone who has done business with or worked for the company should treat this event as potentially relevant to them until more specific notifications are issued.

What Information Was Potentially Exposed?

The specific categories of data accessed during this attack have not been fully detailed in public disclosures. However, ransomware attacks against manufacturing companies commonly result in the theft of both personal and operational information.

Based on the nature of the company’s operations and the type of attack claimed, the following categories of information may be at risk:

  • Employee personal information, potentially including names and contact details
  • Human resources records tied to current or former staff
  • Internal business and manufacturing documents
  • Client or vendor contact information
  • Proprietary design or production data related to aerospace and medical parts

If personal employee data was included in the stolen files, affected individuals could face heightened risk of identity theft. For example, stolen names combined with other identifiers can allow criminals to open fraudulent accounts or file false tax returns.

Beyond personal risk, the exposure of proprietary manufacturing or client data could create competitive and security concerns. Because the company serves defense and aerospace clients, any leaked technical specifications could raise national security implications as well as business risk.

What is the company doing?

In response to the attack, American Casting Company has acknowledged the breach and is presumably working with cybersecurity professionals to contain the incident. Companies facing ransomware attacks typically isolate affected systems, reset credentials, and strengthen network defenses to prevent further unauthorized access.

As part of standard breach response, the company likely notified impacted individuals in September 2026, consistent with the confirmed notification timeline. Moving forward, American Casting Company may offer additional guidance or protective services to those affected, though specific offerings have not been publicly detailed. Affected individuals should watch for official communication directly from the company regarding any monitoring services or further steps.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to American Casting Company, whether as an employee or business partner, should check their credit reports regularly. This helps catch any suspicious new accounts or inquiries early.

You can request a free credit report from each of the three major credit bureaus. Because fraud can take time to surface, checking every few months for the next year is a smart precaution.

Consider a Fraud Alert or Credit Freeze

If personal identifying information was part of the stolen data, placing a fraud alert on your credit file adds an extra layer of protection. This makes it harder for identity thieves to open new accounts in your name.

A credit freeze offers even stronger protection by restricting access to your credit file entirely. As a result, most lenders won’t be able to approve new credit without your explicit permission, which can stop fraud before it starts.

Stay Alert for Phishing Attempts

After a data breach, scammers often use stolen contact information to send convincing phishing emails or texts. Therefore, be cautious of unexpected messages claiming to be from American Casting Company or related organizations.

Never click links or provide personal details in response to unsolicited messages. Instead, verify any communication by contacting the company directly through official channels you trust.

Review Financial and Employment Records

If you’re a current or former employee, review your pay stubs, tax documents, and benefits statements for any irregularities. This can help you spot unauthorized changes or unfamiliar activity tied to your employment records.

In addition, consider reviewing your Social Security statement periodically. Doing so helps confirm that no one has used your information to report false income under your name.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →