On June 15, 2026, Canadian gutter protection manufacturer Alu-Rex appeared on the leak site of the ransomware group BrainCipher. The company, based in Quebec and known for aluminum eavestrough guards sold across North America, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, anyone who has done business with the firm, from contractors to homeowners, may now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch alu-rex.com
Get alerted the next time alu-rex.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about alu-rex.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that BrainCipher posted data stolen from Alu-Rex on its dark-web leak site. The files are described as internal company documents obtained after the attackers encrypted systems and demanded payment. No customer count has been released, and the precise data types have not been independently verified beyond the general description of internal files. The listing appeared on June 15, 2026, consistent with the group’s pattern of publishing samples when victims do not pay.
Why This Matters for You and Your Family
When a local supplier like Alu-Rex suffers a breach, the ripple effects reach ordinary households. Contractors who bought gutter systems, homeowners who provided addresses and contact details for installations, and anyone whose information passed through the company’s systems could find their data circulating. Addresses, phone numbers, email accounts, and payment records are common in vendor files. Once exposed, this information can be combined with other leaks to build a profile that puts your family at higher risk of identity theft, phishing, or physical targeting. Even if you do not remember dealing directly with Alu-Rex, subcontractors or roofing companies often share customer lists, meaning your data may have traveled further than you realize.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one company’s files. Attackers and subsequent data brokers frequently link newly exposed records to usernames, gaming handles, and family member details already circulating on underground forums. A single address or phone number from an Alu-Rex file can anchor an identity chain that reveals your children’s online accounts or your own reused credentials across services. Credential leaks like this one routinely cascade into account takeovers on email, banking, and gaming platforms. Public reporting shows that such chains often lead to doxxing attempts, where personal details are published to pressure victims or for harassment. Protecting every link in that chain is now essential for ordinary families.