Skip to content

Settra claims American Color Imaging after Iowa outage

Summary

American Color Imaging experienced a systems outage from June 24 to July 1, 2026, that paused production, held submitted orders, delayed customer communications and disabled an ordering platform. Settra publicly claimed on July 16 that it stole 653 GB of data, but ACI has not confirmed a cyberattack, unauthorized access, data theft or the actor’s involvement.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Impacted location

Incident characteristics

Assessments

Status:
Resolved
Incident confidence:
Medium
Ransomware:
Low
Attribution:
Low

DD-CIT classification

XC-OC-ODExternal cyber → officialOfficial disruptionAbout the DD-CIT methodology

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Manufacturing or production disruption

    Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

Extortion indicators

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

American Color Imaging experienced a material systems outage beginning June 24, 2026, that affected its ACI and Background Town operations in Cedar Falls, Iowa. DysruptionHub’s published report documented company updates saying orders could still be submitted, but production was paused, submitted work was held, customer communications were delayed and an ordering platform was offline while restoration continued.

Settra publicly listed American Color Imaging’s acilab.com domain on July 16 and claimed it obtained 653 gigabytes of financial, payroll, client and third-party documents. The actor displayed document screenshots and threatened additional publication after a countdown. The claim has not been independently verified, and American Color Imaging has not confirmed unauthorized access, data theft, encryption or a connection between Settra and the outage.

DysruptionHub assesses with medium confidence that the outage and extortion claim concern the same underlying incident. The victim identity and timing support that assessment, but the public record does not establish when malicious activity began or whether Settra caused the operational disruption.

Operational significance

The outage impaired core production and order-fulfillment functions for approximately one week. ACI continued accepting submissions, but production stopped, work accumulated and an online ordering application was unavailable. These conditions delayed service to photography studios and other customers even though the company retained partial order intake.

American Color Imaging reported production fully operational on July 1. That supports a resolved operational status and the July 1 end date for documented material impact. The company did not publish a separate confirmation that the held-order backlog, customer communications and every ordering function had returned to normal.

Disclosure posture

American Color Imaging acknowledged and documented the outage but did not characterize it as malicious or cyber-related. The cyber characterization and attribution came from Settra’s external claim and subsequent reporting. This supports an externally characterized cyber incident with organization acknowledgement of the same disruption, not an official victim cyber disclosure.

Confidence and uncertainty

Confidence is high that the outage disrupted production, order handling, customer communications and an ordering platform because the company’s updates documented those effects. Confidence is medium that malicious cyber activity was involved and low that Settra was responsible because the actor claim identifies the same victim and appeared shortly after the outage, but no victim, forensic, regulator or law-enforcement source has corroborated the linkage.

Ransomware confidence remains low. Settra’s activity supports a data-extortion claim and public leak threat, but public evidence does not confirm encryption, malware deployment, a direct ransom demand, payment or verified publication of the claimed archive. Document screenshots are actor-provided samples, not independent proof that 653 GB was stolen.

Analytic gaps

The reviewed public record does not establish the intrusion start, initial-access vector, affected systems or accounts, malware or tools, persistence, encryption status, attacker dwell time, restoration method, ransom demand or payment. It also does not establish whether the claimed data is authentic, whether information was exfiltrated or later published, which people or organizations were affected, or whether notification obligations arose.

American Color Imaging disclosed a separate cybersecurity incident in May 2025. The reviewed evidence does not connect that earlier event to the June 2026 outage, and the 2025 breach notice does not establish data impact in this case.

Threat actor and claim

Listed as: acilab.comSource: ransomware.livePublished: Discovered:

Claim details

Settra publicly listed acilab.com on July 16, claimed theft of 653 GB and threatened additional publication after a countdown. The claim and its connection to American Color Imaging’s June outage remain unverified.

Screenshot documenting Settra claim

Organizations involved

Impacted location

Source

Settra ransomware group claims American Color Imaging after weeklong Iowa outage
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

American Color Imaging documented a June 24-July 1 systems outage that paused production, held submitted orders, delayed communications and disabled an ordering platform. Settra’s July 16 claim alleged theft of 653 GB and threatened additional publication, but ACI did not confirm cyber activity, data theft, encryption or attribution.