Skip to content
safemode.space
All incidents
2023-03-13 (approximate)
supply chain compromise
supply chain

LockBit claim against SpaceX supplier Maximum Industries (2023)

Confidence in this reading:
low

What happened

In mid-March 2023 the LockBit ransomware operation listed Maximum Industries, a Texas contract manufacturer offering waterjet and laser cutting and CNC machining services, and claimed to have obtained approximately 3,000 drawings certified by SpaceX engineers from the company's systems. LockBit stated it would auction the material to other manufacturers and addressed the claim publicly to SpaceX. Neither SpaceX nor Maximum Industries responded to press enquiries. No independent verification of the claim has been reported: SecurityWeek noted at the time that it is not uncommon for cybercrime groups to make exaggerated claims about the impact of their attacks or the value of the data they have obtained. No cited source confirms that any encryption of Maximum Industries' systems took place, that the auction proceeded, or that the material is what LockBit said it was.

Everything material in this record is a criminal group's unverified claim, and the two edges are marked low and derived to say so. The prior batch's gap analysis assessed this incident as marginal and observed that the corpus already carries two edge-less records for exactly this shape, which is a fair reading and the editor may prefer it. The reason this record maps two edges rather than none, unlike arsat-play-ransomware-2022 in the same batch, is a real distinction: LockBit described a specific artefact class, engineering drawings held at a named contractor, whereas at ARSAT no party described the contents of anything. A described artefact class from an interested and unreliable party is thin evidence, but it is evidence of a different kind from silence. Both edges are written so that a reviewer who rejects the claim can drop them without touching the rest of the record. SCOPE UNDETERMINED, recorded 2026-08-23. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space-sector organisation is expressly not the test. What the sources establish is that a ransomware operation made a claim and that nobody has confirmed it. LockBit listed a Texas contract manufacturer and said it held roughly 3,000 "drawings certified by space-x engineers"; one cited source reports that a leaked file appears to be part of a Raptor V2 engine schematic. Neither SpaceX nor Maximum Industries responded to press enquiries, no independent verification has been reported, and the primary source itself notes that it is not uncommon for such groups to make exaggerated claims. What no cited source establishes is that any system beyond the manufacturer's own was reached. The open question is narrower than that and it is not about this record alone: the boundary ruling excludes a victim that "operates no spacecraft and holds no space asset", which has two limbs, and this manufacturer plainly satisfies the first while the second turns on whether certified production drawings for a launch vehicle engine, held by the shop that machines the parts, are a space asset in the attack path. That has never been construed, and answering it moves at least five published records together rather than this one. A source placing the intrusion, or a follow-on use of the material, inside a SpaceX system would settle it one way; a determination that design data held at a supplier is not a space asset would settle it the other. This record was before the founder on the day the boundary was ruled, as editorial question 8, and was kept. The record stays published while the question is open, under decisions entry 189.

Attack vector

Not established. No cited source describes how Maximum Industries was reached, and no source confirms an encryption event.

Operational impact

None reported. No cited source reports any effect on SpaceX operations, launches or spacecraft.

Data compromised

Claimed only: approximately 3,000 drawings said by LockBit to be certified by SpaceX engineers. Unverified by SpaceX, by Maximum Industries or by any independent party.

Affected segments

supply_chain

Disclosed

2023-03-13

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • EXF-0008 covers breaching a contractor's environment to reach documentation and engineering material that is often more complete than the mission owner's own archives, and notes this typically occurs during production. A parts manufacturer holding certified customer drawings is that position in the chain. The edge is derived because no source describes the compromised environment at all, and low for the same reason the REC-0001 edge is low: the compromise, the exfiltration and the nature of the material all rest on LockBit's unverified account.

    https://www.securityweek.com/ransomware-group-claims-theft-of-valuable-spacex-data-from-contractor/

  • LockBit claimed approximately 3,000 drawings certified by SpaceX engineers, taken from a contract manufacturer that makes parts. REC-0001's subject is assembling a coherent picture of the spacecraft and its ecosystem, and it names drawings and as-built material among the artefacts adversaries seek, including from contractors. The artefact class the claim describes is squarely the technique's. The edge is derived and low because the entire basis is the claim of an interested criminal party: no drawing has been shown, neither SpaceX nor Maximum Industries has confirmed anything, and the reporting source itself cautions that such groups exaggerate.

    https://www.securityweek.com/ransomware-group-claims-theft-of-valuable-spacex-data-from-contractor/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • LockBit is a ransomware operation, which makes this the expected mapping, and it is wrong twice over. No cited source reports that Maximum Industries' systems were encrypted: the reporting covers a leak-site listing and a theft claim. And SPARTA's EX-0010.01 is ransomware executing on a spacecraft, encrypting mass memory, command tables and on-board ephemerides.

  • An Initial Access technique about inserting malicious code, data or configuration during manufacturing, integration or delivery so it reaches the spacecraft. Nothing was reported inserted. This was, on the claim's own terms, an intrusion to take information out.

  • Same defect as the parent, plus: Maximum Industries is described as a cutting and machining subcontractor, and nothing connects the claimed material to a delivered hardware item, let alone a tampered one.

  • SPARTA's IMP-0006 concerns data gathered, processed and sent from the victim spacecraft. Pre-production engineering drawings are not that. The claimed exfiltration is carried by the EXF-0008 edge.

  • Considered because the victim is a supplier. REC-0008 requires the adversary to be mapping the supply chain, and nothing suggests LockBit was: on the reporting, it compromised a company opportunistically and discovered whose drawings it held. Being in a supply chain is not being reconnoitred as one.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.