What Happened
The Settra ransomware group added Teletek Structures Inc. to its extortion leak site on September 3, claiming exfiltrated data from an intrusion researchers estimate began around mid-August. Teletek is a telecommunications engineering firm headquartered in St. Jacobs, Ontario, founded in 2005, providing structural design, drafting, and inspection services for rooftop installations, monopoles, and guyed towers used by Bell Mobility, Rogers Communications, Telus Mobility, and other carriers building out 5G networks across Canada and parts of the United States. Settra’s leak-site statement names the company directly and references its cell tower work across North America. Teletek has issued no public confirmation, and the scope of the claimed data has not been independently verified. Coverage is available from DeXpose.
Why This Matters for Canadian Organizations
Teletek sits inside the engineering supply chain for wireless infrastructure serving Canada’s three largest carriers, a position where a single compromised vendor touches drawings, inspection records, and project data tied to towers supporting emergency communications and cellular coverage nationwide. Settra is a relatively new extortion group, and naming a specialized 20-year-old Canadian engineering firm signals ransomware operators continue treating niche infrastructure contractors as high-value targets, precisely because they sit downstream of carriers with far larger security budgets. If engineering drawings, site access details, or employee records surface in a published leak, Teletek faces notification duties under Ontario’s privacy framework and PIPEDA, and downstream carriers relying on its designs face their own vendor-risk review obligations. Boutique engineering firms supporting telecom infrastructure often run smaller IT teams than the carriers they serve, a gap ransomware groups have learned to target as an entry point into the wider telecom supply chain.
What to Do
Engineering and infrastructure contractors working with major carriers should inventory which client data, drawings, and access credentials sit on internet-facing systems, and separate project files from general corporate email and finance systems so a single compromised account does not expose the full client portfolio. Confirm backups for project archives and CAD files are stored offline or immutable, since extortion groups increasingly rely on publication threats rather than encryption to force payment. Enforce multi-factor authentication across remote access and cloud storage accounts, and review vendor contracts to confirm breach-notification obligations flow correctly between contractors and the carriers they serve. Carriers relying on third-party engineering firms should confirm their vendor risk assessments account for smaller, specialized suppliers rather than only large IT vendors. Updates are available from DeXpose.






