Jewett-Cameron Trading Company, a leading manufacturer and distributor of fencing, pet, and industrial wood products, experienced a significant cybersecurity incident involving a ransomware attack. On October 15, 2025, the company detected unauthorized access to its IT environment, which was later disclosed in an SEC 8-K filing. The attackers deployed encryption and monitoring software on portions of the company’s internal corporate systems, disrupting business applications and limiting access to certain operational and corporate functions. As a precaution, Jewett-Cameron voluntarily took some systems offline to contain the incident. The ransomware gang exfiltrated sensitive data, including images of video meetings, computer screens, and non-public financial documents, some of which were being prepared for the company’s annual SEC report. The threat actors threatened to publicly release the stolen information unless a ransom was paid, increasing the pressure on the company. The company’s 8-K filing confirmed that law enforcement was notified and external cybersecurity experts were engaged to assist with the investigation and recovery efforts. The breach’s full impact on records and data types remains under investigation, but it is confirmed that sensitive company information was accessed and exfiltrated. The company’s operations were disrupted, though the incident was reported as contained at the time of disclosure. Jewett-Cameron’s response included activating its cyber incident response process, assessing the scope of the breach, and implementing remedial measures to secure its systems. The company did not disclose whether any ransom was paid or if any data had been released by the attackers. The incident occurred during a critical period as the company was preparing its annual financial filings, potentially increasing the risk of exposure of sensitive financial data. The company’s public communications emphasized its commitment to transparency and regulatory compliance by promptly filing the required SEC disclosure. The attack highlights the ongoing threat of ransomware to manufacturing and distribution companies, particularly those handling sensitive financial and operational data. The use of monitoring software by the attackers suggests a period of surveillance prior to data exfiltration and encryption, indicating a sophisticated approach. The company’s swift engagement with law enforcement and cybersecurity professionals reflects best practices in incident response. The long-term impact on Jewett-Cameron’s business operations, reputation, and regulatory standing remains to be fully assessed as the investigation continues. The incident underscores the importance of robust cybersecurity measures and incident response planning for organizations in the manufacturing and distribution sectors.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
By October 23, 2025, coverage described the incident as a ransomware attack that disrupted Jewett-Cameron's operations. This represented a clearer public characterization of the attack's operational impact.
Reporting on October 22, 2025 said a ransomware group had stolen sensitive data from Jewett-Cameron, including meeting videos and financial information tied to the fence wholesaler. This added public details about the nature of the data allegedly taken.
Jewett-Cameron Trading Company disclosed a cybersecurity incident affecting its environment in a filing reflected by incident trackers on October 21, 2025. The disclosure marked the first public acknowledgment of the incident.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourceboard-cybersecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.