DL E&C Data Breach

Alleged

Ransomware claim involving DL E&C

Published: Aug 17, 2026 Panzer
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
DL E&C
Industry
Manufacturing
Threat Actor
Panzer
Date of Incident
Aug 17, 2026

Executive Summary

On August 17, 2026, the Panzer ransomware group listed DL E&C, a prominent South Korean construction giant, on its dark web leak portal. The claim was identified by SOCRadar’s Dark Web Monitoring service and currently remains unverified. DL E&C, a subsidiary of a major conglomerate, operates extensively in civil engineering, building construction, and plant development across Asia and the Middle East. Its significant presence and scale make it a notable target, and this incident marks Panzer’s second claim against a Korean organization in its current targeting cycle. In the 60 days prior to this listing, Panzer had claimed 11 other victims, primarily focusing on the Manufacturing, Technology, and Government & Defense sectors. The group’s recent geographic focus has been on Thailand, Spain, and South Korea. Prior to DL E&C, Infosat was another Korean organization targeted by Panzer. Other recent victims include Doimo Cucine, Alpine Electronics Europe, and Castilla La Mancha. DL E&C stands out as the largest and most complex entity claimed by Panzer within their recent Korean targeting efforts.

Technical Analysis

SOCRadar’s investigation revealed seventeen records associated with the domain dlenc[.]co.kr within its stealer-log telemetry. Of these, four records were classified as employee-on-org-systems. Specifically, two records targeted Microsoft Entra ID (login.microsoftonline.com) with confirmed @dlenc[.]co.kr email addresses, and two additional corporate user credentials were found on internal infrastructure. The remaining eleven records involved external or numeric usernames and were associated with various internal portals, including mplan.dlenc[.]co.kr (internal planning), mobileas.dlenc[.]co.kr (mobile asset management), partner.dlenc[.]co.kr (supplier portal), and ehr-recruit.dlenc[.]co.kr (HR recruitment). The logged credentials span from July 10 to August 12, 2026, indicating a concentrated period of active credential harvesting rather than the exposure of older, potentially rotated credentials. The presence of two @dlenc[.]co.kr Microsoft Entra ID accounts in stealer logs necessitates immediate session revocation and a thorough audit. Compromised cloud-tenant sessions can grant access to critical services such as SharePoint, Teams, and internal SaaS applications without necessarily triggering standard perimeter security measures. Following the containment of the Entra ID accounts, the scope of the identity hygiene review should be expanded to include the partner and HR portals to address the eleven other identified credential exposures.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.