Company Details
cooper-steel-usa
232
13,555
23
coopersteel.com
0
COO_7067528
In-progress


Cooper Steel Company CyberSecurity Posture
coopersteel.comAt Cooper Steel, our reputation is built on more than just our services. For more than six decades, clients have trusted us to deliver precision craftsmanship and quality throughout every project stage including estimating, fabrication, erection, project management, and detailing. With grit and determination, we tackle every project head-on, ensuring our customers' expectations are exceeded at every touchpoint.
Company Details
cooper-steel-usa
232
13,555
23
coopersteel.com
0
COO_7067528
In-progress
Between 600 and 649

Cooper Steel Global Score (TPRM)XXXX

Description: Cooper Steel Fabricators, a prominent U.S.-based structural steel fabricator serving high-profile clients like Amazon, suffered a significant data breach. A threat actor claimed to have exfiltrated a complete mirror of the company’s FTP server (330 GB), including proprietary 3D models, engineering drawings, and structural specifications for critical projects. Among the compromised data were hyperscale data center designs for Amazon’s Ohio facility, structural details for Publix Greensboro Refrigerated Distribution Center, and blueprints for Walmart distribution centers, cold storage facilities, and a Massachusetts-based Amazon sorting hub.The attacker demanded $28,500 in cryptocurrency for the stolen data, which includes sensitive intellectual property (IP) vital to Cooper Steel’s operations and client trust. The breach exposes not only the company’s internal project documentation but also confidential client infrastructure details, risking competitive disadvantage, reputational harm, and potential legal liabilities. As of now, Cooper Steel has not publicly acknowledged the breach, leaving the extent of operational or financial fallout uncertain. The incident underscores vulnerabilities in supply chain security, particularly for firms handling critical infrastructure designs for tech and logistics giants.
Description: Cooper Steel Fabricators, a prominent U.S.-based structural steel fabricator serving high-profile clients like Amazon, suffered a significant data breach. A threat actor claimed responsibility, exfiltrating a complete mirror (330 GB) of the company’s FTP server likely containing proprietary designs, contracts, financial records, or operational data. The attacker demanded $28,500 in cryptocurrency for the stolen data, posing risks of intellectual property theft, competitive disadvantage, or further exploitation if the data is leaked or sold. The breach exposes the company to financial loss (ransom payment or recovery costs), reputational damage among clients (e.g., Amazon), and potential legal liabilities if sensitive third-party data was compromised. The scale of the exfiltrated data suggests a targeted attack aimed at crippling operations or extracting maximum value, with long-term consequences for trust and business continuity.


No incidents recorded for Cooper Steel in 2026.
No incidents recorded for Cooper Steel in 2026.
No incidents recorded for Cooper Steel in 2026.
Cooper Steel cyber incidents detection timeline including parent company and subsidiaries

At Cooper Steel, our reputation is built on more than just our services. For more than six decades, clients have trusted us to deliver precision craftsmanship and quality throughout every project stage including estimating, fabrication, erection, project management, and detailing. With grit and determination, we tackle every project head-on, ensuring our customers' expectations are exceeded at every touchpoint.


Skanska Group uses knowledge & foresight to shape the way people live, work, and connect. More than 138 years in the making, we’re one of the world’s largest development and construction companies, with 2024 revenue totaling SEK 177 billion. We operate in select markets throughout the Nordics, Europ

Premier groupe français et acteur mondial de premier plan de la construction, VINCI Construction réunit plus de 830 entreprises et près de 69000 collaborateurs dans une centaine de pays. Ses expertises s’étendent à l’ensemble des métiers du bâtiment, du génie civil, et des activités spécialisées ass
America's Builder is a lofty title, but it's a goal we work toward every day. D.R. Horton started in 1978 in Fort Worth, Texas, and has grown into a national Fortune 500 company. Since 2002, D.R. Horton has been the number one homebuilder in America. We build across the country, bringing our home
Bechtel is a trusted engineering, construction and project management partner to industry and government. Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers’ objectives to create a lasting positive

Across decades, across disciplines, NCC Ltd has dedicated itself to building infrastructure of uncompromising standards. Infrastructure that is a constant reminder of the Company’s holistic construction expertise, which in turn is the result of relentless innovation and sheer dedication. Today, NCC

At Kiewit, the projects we deliver make a difference, and we offer opportunities for you to make one, too. Our construction and engineering professionals work on some of the industry’s most complex, challenging and rewarding projects – whether it’s boring tunnels through mountains, turning rivers in

Bouygues Construction employs 35,600 people around the world, all driven by the greatest and most exciting responsibility of all – building for life. For our customers in more than 50 countries, we deliver much more than projects. We build to create spaces, connections and opportunities. We impro
The IBEW represents 860,000 active. and retired who work in a wide variety of fields, including utilities, construction, telecommunications, broadcasting, manufacturing, railroads and government. The IBEW has members in both the United States and Canada and stands out among the American unions in t

Holcim is the leading partner for sustainable construction, creating value across the built environment from infrastructure and industry to buildings. We offer high-value end-to-end Building Materials and Building Solutions - from foundations and flooring to roofing and walling - powered by premium
.png)
Mike Philbrick, CEO, ReSolve Asset Management. Focus: Exchange-Traded Funds. ADVERTISEMENT. Top picks: iShares Silver Bullion ETF,...
The Trump administration says that the tariffs on metals imports are aimed at boosting domestic industries and addressing "trade imbalances.
The sector-specific tariffs are putting pressure on businesses and foreign nations as they try to navigate Trump's constantly evolving trade...
Imports of steel, aluminium, copper and specific minerals not available in the US are exempt from the reciprocal tariff.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Cooper Steel is http://www.coopersteel.com.
According to Rankiteo, Cooper Steel’s AI-generated cybersecurity score is 641, reflecting their Poor security posture.
According to Rankiteo, Cooper Steel currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Cooper Steel has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Cooper Steel is not certified under SOC 2 Type 1.
According to Rankiteo, Cooper Steel does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Cooper Steel is not listed as GDPR compliant.
According to Rankiteo, Cooper Steel does not currently maintain PCI DSS compliance.
According to Rankiteo, Cooper Steel is not compliant with HIPAA regulations.
According to Rankiteo,Cooper Steel is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Cooper Steel operates primarily in the Construction industry.
Cooper Steel employs approximately 232 people worldwide.
Cooper Steel presently has no subsidiaries across any sectors.
Cooper Steel’s official LinkedIn profile has approximately 13,555 followers.
Cooper Steel is classified under the NAICS code 23, which corresponds to Construction.
No, Cooper Steel does not have a profile on Crunchbase.
Yes, Cooper Steel maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cooper-steel-usa.
As of January 24, 2026, Rankiteo reports that Cooper Steel has experienced 2 cybersecurity incidents.
Cooper Steel has an estimated 39,311 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: Cooper Steel Fabricators Data Breach and FTP Server Leak
Description: Cooper Steel Fabricators, a U.S.-based structural steel fabricator serving clients like Amazon, was allegedly breached by a threat actor. The actor offered a 'complete mirror' of the company's FTP server (330 GB of data) for $28,500 in cryptocurrency. The leaked data reportedly includes 3D models, drawings, and structural specifications for high-profile projects such as Amazon's Ohio data center (hyperscale operations), Publix Greensboro Refrigerated Distribution Center, Walmart distribution centers, cold storage facilities, and a Massachusetts-based Amazon sorting facility. Cooper Steel has not yet acknowledged the breach claims.
Type: data breach
Threat Actor: Type: cybercriminal (extortionist)Motivation: ['financial gain', 'data monetization']
Motivation: financial gaindata sale
Title: Cooper Steel Fabricators Data Breach and Extortion Attempt
Description: Cooper Steel Fabricators, a leading U.S. structural steel fabricator serving clients like Amazon, was breached by a threat actor. The attacker claimed to possess a 'complete mirror' of the company's FTP server (330 GB of data) and demanded $28,500 in cryptocurrency in exchange for not leaking the data.
Date Publicly Disclosed: 2025-11-25
Type: data breach
Threat Actor: Type: extortionistMotivation: financial gain
Motivation: financial gain
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: 3d models, Drawings, Frames, Structural specifications (e.g., hyperscale data center operations), Project data for publix greensboro refrigerated distribution center, Amazon ohio data center details, Massachusetts-based amazon sorting facility data, Walmart distribution center data, Cold storage facility data
Systems Affected: FTP server
Brand Reputation Impact: potential (unconfirmed; breach claims unacknowledged)

Data Compromised: 330 GB (FTP server contents)
Systems Affected: FTP server
Brand Reputation Impact: potential (due to public disclosure of breach and extortion)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Proprietary Engineering Data, 3D Models, Drawings, Structural Specifications, Project Documentation, and FTP server contents (330 GB).

Entity Name: Cooper Steel Fabricators
Entity Type: private company
Industry: structural steel fabrication
Location: United States
Customers Affected: Amazon (Ohio data center, Massachusetts sorting facility), Publix (Greensboro Refrigerated Distribution Center), Walmart (distribution centers, cold storage facilities)

Entity Name: Amazon
Entity Type: corporation (client of Cooper Steel)
Industry: e-commerce/cloud services
Location: United States

Entity Name: Publix
Entity Type: corporation (client of Cooper Steel)
Industry: retail/grocery
Location: United States (Greensboro, NC)

Entity Name: Walmart
Entity Type: corporation (client of Cooper Steel)
Industry: retail
Location: United States

Entity Name: Cooper Steel Fabricators
Entity Type: private company
Industry: structural steel fabrication
Location: United States

Type of Data Compromised: Proprietary engineering data, 3d models, Drawings, Structural specifications, Project documentation
Sensitivity of Data: high (proprietary client project details, hyperscale data center specifications)
File Types Exposed: CAD filesPDFsproject documentsFTP server files

Type of Data Compromised: FTP server contents (330 GB)

Ransom Demanded: $28,500 (in cryptocurrency)
Data Exfiltration: True

Ransom Demanded: $28,500 (in cryptocurrency)
Data Exfiltration: True

Source: Cybernews
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Cybernews, and Source: CybernewsDate Accessed: 2025-11-25.

Investigation Status: unconfirmed (Cooper Steel has not acknowledged the breach)

High Value Targets: Amazon Hyperscale Data Center Specifications, Publix Distribution Center Designs, Walmart Infrastructure Data,
Data Sold on Dark Web: Amazon Hyperscale Data Center Specifications, Publix Distribution Center Designs, Walmart Infrastructure Data,

High Value Targets: Ftp Server,
Data Sold on Dark Web: Ftp Server,
Last Ransom Demanded: The amount of the last ransom demanded was $28,500 (in cryptocurrency).
Last Attacking Group: The attacking group in the last incident were an Type: cybercriminal (extortionist)Motivation: ['financial gain', 'data monetization'] and Type: extortionistMotivation: financial gain.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-11-25.
Most Significant Data Compromised: The most significant data compromised in an incident were 3D models, drawings, frames, structural specifications (e.g., hyperscale data center operations), project data for Publix Greensboro Refrigerated Distribution Center, Amazon Ohio data center details, Massachusetts-based Amazon sorting facility data, Walmart distribution center data, cold storage facility data, and 330 GB (FTP server contents).
Most Significant System Affected: The most significant system affected in an incident was FTP server and FTP server.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 3D models, cold storage facility data, structural specifications (e.g., hyperscale data center operations), 330 GB (FTP server contents), drawings, Massachusetts-based Amazon sorting facility data, Amazon Ohio data center details, project data for Publix Greensboro Refrigerated Distribution Center, Walmart distribution center data and frames.
Most Recent Source: The most recent source of information about an incident is Cybernews.
Current Status of Most Recent Investigation: The current status of the most recent investigation is unconfirmed (Cooper Steel has not acknowledged the breach).
.png)
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.