SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach LOCKHEED-MARTIN-IR 2026-08-21

Lockheed Martin: Iran-Linked APT IRAN Discounts an Unverified 375TB Data Trove

"An Iran-aligned persona calling itself APT IRAN has cut the asking price on a claimed Lockheed Martin data haul by as much as 95%, according to Threat Beat, which reported on Aug. 20, 2026 that the group is now offering…"

An Iran-aligned persona calling itself APT IRAN has cut the asking price on a claimed Lockheed Martin data haul by as much as 95%, according to Threat Beat, which reported on Aug. 20, 2026 that the group is now offering 375TB of alleged defense-contractor material for $18,000,000 to a single buyer, down from a listed $374,821,400. There are no free samples: the group says a sample package costs $1,000,000. Critically, none of the available sources include a statement from Lockheed Martin, a regulatory filing, or a government confirmation that any such breach occurred. The cache's authenticity is unestablished, and the actor behind it has a documented history of claim-driven activity that outruns what can be verified.

What Happened

The Lockheed Martin claim is not new. Threat Beat reports that APT IRAN first surfaced it earlier in the year, posting the alleged trove for sale on a Russian- and English-language dark web marketplace. On March 22, the group released an email purported to come from a senior Lockheed Martin official, accompanied by a video showing access to the alleged inbox. On March 23 it demanded roughly $400 million from the United States, framing the figure as "the cost of building four F-35 fighters," then raised the price. On April 7 it revived the claim on Telegram with the line, "Lockheed knows very well how far we've gone and what information we have access to." The August discount is the latest move in that sequence.

Accounts of who is targeting Lockheed Martin diverge, and the two claims should not be conflated. Separately from APT IRAN's corporate-data claim, the Handala Hack Team, which the U.S. government has accused Iran's Ministry of Intelligence and Security of operating, has claimed to hold data on U.S.- and Israel-based Lockheed Martin employees and threatened to publish personal details about their families, children, and locations. Counsel magazine reports that Lockheed Martin employees were contacted by telephone and threatened with the release of details about their families and children. The FSBC analysis states plainly that "the Lockheed Martin claims remain unverified." Two Iran-linked personas, two different claims, one unconfirmed victim.

The discount also lands in a week of concrete legal action against Iranian operators, though on an unrelated case. On Aug. 19, 2026, the U.S. charged 17 Iranians tied to the Mabna Institute, a hacking-for-hire operation, adding eight names to nine charged in a March 2018 indictment. Reporting on the volume differs in framing: Help Net Security says the group stole more than 31 terabytes of academic data and intellectual property and notes the DoJ figure of more than $3.4 billion as what U.S. universities spent to procure and access that material, while BleepingComputer's headline presents the $3.4 billion as the value of the intellectual property theft itself. The indictment describes a campaign running from approximately 2013 through at least December 2017 against 144 U.S. universities, 178 foreign universities, at least 42 U.S. private companies and 11 foreign ones, at least five U.S. federal and state agencies, and at least two NGOs, targeting upwards of 100,000 professor email accounts and compromising roughly 8,000. DoJ announced rewards of up to $10 million for information locating five of the defendants.

What Was Taken

Nothing has been confirmed taken from Lockheed Martin. What exists is a claim and a price list.

APT IRAN describes the March haul as including technical documentation from active military projects, confidential contracts, high-level personnel information, and sensitive administrative emails, sized at 375TB in the August listing. The only offered proof points are the March 22 email attributed to a senior company official and the accompanying inbox video, neither independently authenticated in the reporting.

The pricing arc is worth reading as intelligence in itself. The March demand of "about $400 million" was later hiked; the August listing shows $374,821,400 falling to $18,000,000, a discount the group itself characterizes as between 50% and 95%. A seller who cuts a nine-figure asking price by more than 95% and simultaneously refuses to release a free sample is not behaving like one holding 375TB of verified F-35-adjacent engineering data. Mallory.ai's profile of the actor notes that much of APT IRAN's publicly visible activity is claim-driven, amplified through social channels, and that multiple incidents attributed to the persona remain unverified.

By contrast, the Mabna Institute figures are the ones anchored in a charging document rather than a Telegram post: 31 terabytes, 8,000 compromised accounts, and a resale operation running two websites that sold stolen material to buyers inside Iran, including public universities, with one site letting paying customers log directly into compromised professor accounts.

Why It Matters

The temptation is to dismiss the Lockheed listing as noise. That is half right and operationally dangerous.

FSBC's analysis makes the point that matters for defenders: even recycled or low-value data can force costly investigations and response efforts. A 375TB claim against a top-tier defense contractor obligates counsel, incident response, government liaison, and executive attention regardless of whether a byte of it is real. That resource drain is the objective. Mallory.ai lists influence operations as APT IRAN's primary motivation, and the group's target set spans Jordan, Israel, the U.S., Bahrain, Kuwait, Saudi Arabia, and the UAE.

The second-order concern is the shift toward targeting individuals. Threats delivered by phone to named employees about their children's locations are a coercion play against the defense industrial base workforce, not a data-monetization play. It works whether or not the underlying data exists.

The third is that the same ecosystem does have demonstrated destructive capability elsewhere. APT IRAN claimed on Aug. 11 in a Telegram statement, since deleted, that "the attack on Minnesota was the work of the CyberAv3ngers group and us, and we take direct responsibility for it," referring to late-July cyberattacks on Minnesota water systems. The deletion of that post is notable and unexplained. Treat the extortion theater as low confidence; treat the OT capability of the surrounding cluster as documented by federal agencies.

The Attack Technique

No intrusion vector has been established for the alleged Lockheed Martin compromise. What is documented is how Iran-linked actors have actually been getting into U.S. critical infrastructure.

Six federal agencies updated a joint CISA advisory on July 22, 2026, originally issued in April 2026, describing ongoing attacks against internet-exposed programmable logic controllers. Per the advisory analysis, attackers scan the internet for exposed PLCs and connect using legitimate manufacturer engineering software, exactly as an authorized technician would, then alter the controllers' underlying ladder logic. In one U.S. victim environment, FBI investigators found the attacker had used configuration software to download a malicious project file to a PLC. The advisory states that "the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim's environment." Operator displays on HMI and SCADA systems were manipulated so personnel could not visually detect anything was wrong.

The July update widened the vendor scope beyond Rockwell Automation and Allen-Bradley to include Schneider Electric and Siemens, and warned that devices from other manufacturers may also be targeted. Investigators are aware of attacks against Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series controllers. Targeted ports were 44818, 2222, 102, 502, and 22. The advisory also added detection guidance for malicious changes hidden inside shared, reusable code modules. Unlike a comparable and largely disruption-free 2023 campaign, this activity has caused confirmed operational disruption and financial loss at some affected organizations across government facilities, water, and energy.

For the intellectual-property side, the Mabna Institute indictment describes years of spearphishing against professor email accounts as the entry point, with stolen credentials then used to pull research papers, theses, dissertations, and academic books across science, engineering, medicine, and the social sciences.

What Organizations Should Do

  1. Do not authenticate a claimed leak by buying a sample. A $1,000,000 sample fee is an extraction mechanism. Route any purported proof material through legal and law enforcement, and validate claimed documents against internal records rather than against the seller's narrative.
  2. Inventory and remove internet-exposed PLCs. Audit for exposure on ports 44818, 2222, 102, 502, and 22, and prioritize Rockwell CompactLogix and Micro850, Schneider Modicon M340 (BMX P34), and Siemens S7-1200 devices named in the July 22 advisory. Place all engineering access behind VPN or a jump host with MFA.
  3. Baseline and monitor ladder logic, including shared code modules. Because the tradecraft uses legitimate engineering software, network detection alone will miss it. Maintain known-good project file hashes, alert on unauthorized project downloads, and follow the advisory's guidance on changes hidden in reusable modules.
  4. Assume HMI and SCADA displays can lie. Build out-of-band physical verification for safety-critical parameters so operators are not relying solely on a screen an attacker may be controlling.
  5. Extend protection to employees personally. Given documented phone-based threats against defense contractor staff and their families, brief the workforce on intimidation calls, provide a single reporting channel, run executive and engineer PII removal from data brokers, and harden personal email with phishing-resistant MFA. The Patel leak showed how mundane personal data gets pivoted into wider account mapping.
  6. Harden the credential-theft path against research and IP theft. The Mabna pattern was spearphishing into email, then bulk document exfiltration. Enforce phishing-resistant MFA on all mail access, alert on anomalous bulk downloads from document repositories, and review third-party and academic collaboration accounts holding IP.
  7. Preserve evidence and coordinate before responding publicly. Capture the marketplace and Telegram artifacts, including deleted posts, and coordinate with the FBI and CISA rather than negotiating or engaging the seller directly.

Sources: Iran hackers launch deep-discount sale on alleged Lockheed Martin d... | Federal Agencies Warn of Ongoing PLC Exploitation Against Critical... | US charges Iranian hackers over $3.4 billion intellectual property... | US charges 17 Iranian hackers over 31-terabyte academic data theft... | US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockw... | APT Iran - Mallory.ai | Iranian Cyber Warfare: Targeting Individuals, Creating Chaos (2026) | The zero-trust approach to cyber security