Quick Summary
AllegedExecutive Summary
Appliance Factory & Mattress Kingdom, a retail and appliance distribution company based in the United States, has been identified on the dark web portal of INC Ransom as a claimed victim. The listing, dated September 17, 2026, was detected by SOCRadar’s Dark Web Monitoring service. The company’s operations in retail and appliance distribution may make it an attractive target for ransomware operations due to the critical nature of its supply chain and customer-facing services. INC Ransom has been notably active, claiming 64 victims in the 60 days preceding this listing. Their primary targets appear to be the Manufacturing, Professional Services, and Healthcare sectors, with a significant focus on organizations in the United States, followed by Canada and Malaysia. Appliance Factory fits well within INC Ransom’s typical targeting pattern, aligning with their prevalent victim demographics and industries. Recent victims with similar profiles include jms building corporation, Cullotta Bravo Law Group, Diarco, and Oleoductos del Valle.
Technical Analysis
SOCRadar’s telemetry detected a severe credential exposure linked to the appliancefactory[.]com domain. A sample of 25 records revealed nine employee credentials on organizational systems, including at least four distinct usernames associated with the @appliancefactory.com domain. The exposed credentials also included four external customer records and five corporate users from third-party services such as Freshworks (CRM), GoToMyPC (remote access), and Freightwise (logistics authentication). The identified credentials span from April 26, 2026, to September 12, 2026. The presence of recurring usernames across multiple platforms over a five-month period suggests a potential persistent infection on a workstation or that compromised credentials have not been rotated since their initial theft. The exposure of credentials for critical services like remote access and CRM platforms represents a significant intrusion risk. The observed credential exposure, particularly for GoToMyPC and Freshworks, carries a high potential for initial access, aligning with the common tactics employed by INC Ransom operators and their affiliates. These threat actors frequently validate stolen credentials against remote access portals and Microsoft 365 accounts before deploying ransomware. The long duration for which some credentials remained exposed indicates a potential window for unauthorized access. Continuous monitoring of dark web stealer logs and proactive credential hygiene measures, including password rotation and multi-factor authentication review, are strongly recommended. An audit of session logs for GoToMyPC and Freshworks, starting from April 2026, is also advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.