Berg – Crushing Corporation of America Data Breach

Alleged

Ransomware claim involving Berg - Crushing Corporation of America.

Published: Jul 9, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Berg - Crushing Corporation of America
Industry
Manufacturing
Threat Actor
Settra
Date of Incident
Jul 9, 2026

Executive Summary

Berg / Crushing Corporation of America has been listed as a victim on the settra ransomware group’s dark web portal, published on July 9, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The dataset does not carry a specific sector for this entity and records its country as Germany; the name points to industrial crushing and materials-processing equipment. It joins a settra portal that has skewed toward business services and Western markets. In the 60 days prior to this listing, settra has claimed 17 other victims across its leak portal. The group has shown a strong targeting pattern in the business services, technology, and consumer services sectors. Geographically, its victims are concentrated in the United States, Germany, and the United Kingdom. Other recent settra listings that overlap with Berg / Crushing Corporation of America’s profile — German or industrial organizations — include Orion Registrar Inc., Joy Construction Corp, Wilfley, and Owensboro Grain Company. Berg fits the German and industrial thread of settra’s recent activity, even if its exact sector is not pinned down in our data.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for bergdemo.com in the queried slice. A null result is not the same as a clean bill of health: the query reflects a partial, paginated sample from a single source, and exposure can hide behind alternate corporate domains, personal email aliases used on work devices, or logs traded and rotated before they were indexed. The queried domain also carries a “demo” label, which raises the possibility that the primary corporate domain differs from the one indexed here — a limited-coverage caveat worth flagging. For ransomware groups such as settra, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The absence of evidence in this query does not rule that scenario out — credentials may have surfaced in feeds outside this dataset, been used and rotated before indexing, or been harvested under a different corporate domain. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than reading a null query as exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.