Quick Summary
AllegedExecutive Summary
SafePay ransomware listed Air Liquide’s South Korean operations as a victim on its dark web portal on August 25, 2026. This listing added a major multinational’s regional subsidiary to a group whose victim set is primarily concentrated in Europe. The incident was identified through SOCRadar’s Dark Web Monitoring. Air Liquide’s South Korean operations are significant, supplying industrial, medical, and specialty gases to manufacturing and healthcare customers across the region. This incident highlights the potential for ransomware groups to target high-value operations beyond their usual geographic focus. SafePay claimed 39 other victims in the preceding 60 days. The group has a notable concentration in the Manufacturing, Business Services, and industrial sectors, with its victims predominantly located in Germany, the United States, and Italy. Recent listings with overlapping manufacturing or Asia-Pacific profiles include CPU AG, South Shore Recycling, Simonrack, and Naskdoor Inc. Air Liquide’s South Korean operations represent a geographic outlier for SafePay, whose victimology has historically been centered in Europe. However, the group has demonstrated a willingness to pursue high-value manufacturing targets across various geographies.
Technical Analysis
A stealer-log telemetry query conducted against industry.airliquide[.]kr, the subdomain for Air Liquide’s South Korean industrial operations, returned no records. It is important to note that for a multinational subsidiary, domain coverage is inherently incomplete. Employees may authenticate through the parent domain (airliquide[.]com), regional single sign-on (SSO) systems, or subsidiary-specific domains that were not included in this particular query. Infostealer-harvested credentials are a known initial access vector for the SafePay group. Threat actors typically source fresh logs from underground markets, validate corporate credentials, and then use them to gain access to VPNs, remote-access portals, or Microsoft 365 tenants before deploying ransomware. The absence of evidence in this specific query does not rule out this scenario. Cybersecurity threat intelligence (CTI) teams monitoring a multinational subsidiary should extend stealer-log queries to include all known domain variants and parent company credentials to ensure comprehensive coverage.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.