C.A. LINDMAN Inc.
Attack Intelligence
C.A. LINDMAN Inc. was compromised in a ransomware attack attributed to dragonforce in March 2026. The organization, operating in the Construction sector in United States, was added to the group's data leak site as part of an extortion campaign.
dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Numerous data items, including financial and project details, were leaked from servers located at the company's headquarters in Florida, Maryland, and North Carolina. C.A. Lindman, Inc., founded in 1990, has grown from a small restoration company with less than 10 employees, into one of the top 20 national firms specializing in exterior concrete and masonry repairs over the last 30 years. The founders, Rob Pusheck and Jeff Procter, have kept Lindman focused on meeting all of their clients’ needs and expectations. The “Lindman Difference” is the company’s motto and delivering this superior service is the company-wide goal every day.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.