A ransomware group published an archive of internal files stolen from a mid-sized defense contractor after the company refused to pay a multi-million dollar extortion demand.

The leaked material reportedly includes engineering schematics, supplier lists and internal correspondence. Government agencies are assessing whether any export-controlled technical data was exposed.

The contractor said its production systems were restored from backups within days and that it coordinated with federal authorities throughout, consistent with official guidance against paying ransoms.

The incident illustrates the double-extortion model now standard among ransomware groups, where data theft precedes encryption and leak threats persist even after systems are recovered.