Kimber Mfg., Inc., the U.S. firearms manufacturer behind the Kimber America brand, is facing an alleged data breach after a cybercrime forum listing claimed that 486GB of internal company data had been stolen and was being offered for sale.
The August 18, 2026 listing claims the archive contains 507,381 files spanning customer information, firearm-related records, invoices, receipts, scanned checks, partner documents, shipping information, and other internal material. The seller priced access at $9,000 and claimed the data was obtained in August.
Kimber had not issued any public statement regarding the alleged 2026 incident at time of publication. BreachNews has not independently verified the claimed archive or confirmed that the files originated from Kimber.
Claimed archive includes firearm transaction and shipping records
The forum post describes the alleged dataset as significantly broader than a standard customer database. According to the listing, application forms within the archive may contain:
- Firearm serial numbers
- Model selections
- Pricing information
- Sales associate names and contact information
- Customer shipping and billing information
- Shipping recipient names, addresses, and phone numbers
- Federal Firearms License information
The seller also claims the archive contains sales verification forms, invoices, receipts, firearm transaction records, partner and affiliate records, earnings statements, and scanned copies of checks.
If authentic, the combination of firearm identifiers, customer information, transaction records, and shipping information would make the alleged exposure particularly sensitive. Such records could potentially reveal relationships between customers, dealers, transactions, and specific firearms.
507,381 files allegedly total 486GB
The seller claims the complete archive contains 507,381 documents totaling approximately 486GB when uncompressed.
Sample images were included with the listing, although BreachNews is not reproducing material containing personal information, transaction identifiers, firearm serial numbers, or other sensitive records.
The post also contains allegations that Kimber was aware of the intrusion and failed to properly notify affected customers or regulators. Those assertions have not been independently substantiated, and BreachNews is not repeating the seller’s attempt to assign personal responsibility for the alleged incident to an individual associated with the company.
Same seller previously targeted fitness companies
The same forum account has recently posted other alleged breach listings, including a BODY20 breach claim involving more than 205,000 member records.
Previous listings from the same account have followed a similar format, combining detailed descriptions of allegedly stolen records with a limited number of sale slots and claims that the affected organizations were aware of the incidents. Those recurring claims do not independently establish the authenticity of the Kimber dataset.
Kimber has disclosed a previous customer data incident
Kimber has previously experienced a separate confirmed security incident. In 2023, the company notified affected individuals after an unauthorized party accessed a software tool used to administer its third-party-managed online store.
Kimber said at the time that the earlier incident potentially exposed customer order information between October 23 and November 7, 2023, including names and payment card information. That incident is separate from the newly alleged 2026 breach.
The current claim is considerably broader, alleging access to hundreds of gigabytes of company information rather than a limited online store exposure.
Manufacturing and customer records raise multiple risks
If the alleged data proves authentic, the exposure could create risks for customers, employees, partners, and firearms dealers whose information may be present in internal records.
Customer contact and transaction data could support targeted phishing or impersonation attempts, while scanned checks and affiliate financial records could create fraud risks. Firearm serial numbers, dealer information, and transaction documents would also represent highly sensitive operational and customer information if included as claimed.
Kimber’s official materials identify the company as a U.S. manufacturer serving individual, sporting, law enforcement, and military markets, with its corporate headquarters located in Troy, Alabama.
BreachNews will update this article if Kimber confirms or disputes the alleged breach or if additional independently verifiable information becomes available.












