Russian-speaking ransomware group Lynx executed a significant cyberattack against Dodd Group, a major UK Ministry of Defence (MoD) contractor, resulting in the theft and subsequent leak of approximately 4 terabytes of sensitive data. The breach targeted Dodd Group, a Shropshire-based firm providing electrical and mechanical services to British military bases, and exposed confidential information related to both the company and the MoD. The stolen data, which the Lynx group began leaking on their Tor data leak site, includes staff names, email addresses, contractors’ names, phone numbers, car registrations, and MoD personnel contact details. Some of the compromised documents were marked as “Controlled” or “Official Sensitive,” indicating the high level of sensitivity and potential national security implications. The leaked files reportedly contain information on at least eight Royal Air Force (RAF) and Royal Navy bases, including RAF Lakenheath, which hosts US F-35 jets and is believed to house nuclear weapons, RAF Portreath, a NATO radar site, and RAF Predannack, the UK’s National Drone Hub. Visitor logs for RAF Portreath and RNAS Culdrose were among the documents exposed, raising concerns about operational security and the safety of military personnel. The attack was described as “catastrophic” by The Daily Mail, highlighting the scale and impact of the breach. The Dodd Group, which employs over 1,100 people and operates across multiple sectors, confirmed the cyber incident and is cooperating with authorities. The UK Ministry of Defence has launched an investigation into the breach, emphasizing its robust and proactive approach to cyberthreats but declining to comment further on operational details. The Lynx group, considered a successor to the INC criminal operation, reportedly began leaking the data after failed negotiations with the victim. The breach has raised alarms about the security of third-party contractors and the potential exposure of sensitive military infrastructure and personnel information. The incident underscores the growing threat posed by ransomware groups targeting critical defense supply chains. The leak of documents related to ongoing projects, such as the installation of oil tanks and new lighting at military bases, further illustrates the operational risks introduced by such breaches. The exposure of sensitive data could have long-term implications for the security posture of the UK’s defense sector. Authorities are assessing the full extent of the compromise and working to mitigate potential risks to national security and military operations.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
The UK Ministry of Defense began investigating the alleged breach involving contractor Dodd Group after reports that stolen data included information connected to military bases and MoD personnel. The case raised concerns about exposure of sensitive defense-related contractor records.
The Russian-speaking Lynx ransomware group posted sample files on its dark web leak site and claimed it stole about 4TB of data from Dodd Group. Reporting said the leaked material included sensitive files tied to at least eight UK military bases.
Dodd Group confirmed it experienced a cyber incident in which data was stolen, though it said the amount taken was limited and that its systems had been secured and recovered. The exposed information reportedly included contractor personal data, MoD personnel names and email addresses, and documents related to work at British military bases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcesecurityaffairs.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.