Lockheed Martin is facing extortion claims from the pro-Iran hacktivist group APT Iran, which said it stole 375 TB of data from the U.S. defense contractor, including alleged F-35 aircraft blueprints and other internal corporate files. The group publicized the alleged breach on Telegram and demanded more than $400 million to keep the material from being sold to U.S. adversaries, according to reporting cited by SC Media, Cybersecurity Dive, and UpGuard.
A web archive of a post attributed to the Handala Hack Team showed the attackers escalating pressure by giving Lockheed Martin employees 48 hours to respond. Lockheed Martin said it was aware of the reports and maintained that it has multilayered security controls in place, adding that it remains confident in the integrity of its information systems and data security. Flashpoint also linked the same threat actor to earlier attacks on Jordanian critical infrastructure, underscoring broader regional and geopolitical risk tied to the campaign.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
A web-archived post on the Handala Hack Team site stated that Lockheed Martin employees had been given 48 hours to respond. The post indicated continued pressure activity tied to the alleged breach and extortion campaign.
Lockheed Martin acknowledged awareness of the reported incident and said it maintains multilayered security measures and policies. The company also said it remained confident in the integrity of its information systems and data security.
Alongside its breach claim, APT Iran said it wanted more than $400 million in ransom to avoid selling the purportedly stolen Lockheed Martin data to U.S. adversaries. This marked an escalation from a theft claim to an extortion threat.
The pro-Iran hacktivist collective APT Iran publicly claimed it had breached Lockheed Martin and stolen 375 TB of data, including alleged F-35 aircraft blueprints and other corporate files. The claim was publicized on Telegram and became the basis for subsequent reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourcescworld.com
Open sourceupguard.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.