UFP Technologies, a Massachusetts-based medical device manufacturer, disclosed in an SEC filing that it detected suspicious activity on its IT systems on February 14 and responded by isolating affected systems, engaging external cybersecurity experts, and launching an investigation. The company reported that the incident impacted many but not all IT systems and disrupted business functions including billing and label making for customer deliveries; it also stated that certain company or company-related data appears to have been stolen or destroyed.
UFP said it believes the intruder has been removed from its environment and that access to impacted information has been restored “in all material respects,” with recovery supported by contingency plans and backup systems. Reporting noted that the combination of apparent data theft and destruction could indicate ransomware or wiper-like activity, though no malware family or threat actor has been publicly identified and no ransomware group had claimed responsibility at the time of publication; UFP also indicated it is still assessing whether sensitive or personal information was exfiltrated and expects cyber insurance to cover most incident-related costs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
UFP publicly reported the incident in an SEC filing, stating that many but not all IT systems were affected, personal-data impact was still under assessment, and the company did not expect a material operational or financial impact.
UFP said the threat actor had been removed from its environment and that access to affected information had been restored in all material respects, including through use of backup data systems.
During its investigation, the company concluded that some company or company-related data appears to have been exfiltrated or destroyed, while functions such as billing and label-making for customer deliveries were affected.
After detecting the intrusion, UFP isolated impacted systems, launched remediation efforts, and engaged external cybersecurity advisors to investigate and contain the attack.
UFP Technologies discovered suspicious activity affecting portions of its IT environment on 2026-02-14, marking the start of the disclosed cybersecurity incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.