DyStar Data Breach

Alleged

Ransomware claim involving DyStar.

Published: Jun 28, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
DyStar
Industry
Consumer Services
Threat Actor
Settra
Date of Incident
Jun 28, 2026

Executive Summary

DyStar, a manufacturing company based in Singapore, was recently targeted by the Settra ransomware group. The listing appeared on Settra’s dark web portal on June 28, 2026, as part of a batch of new victims. SOCRadar’s Dark Web Monitoring service identified this listing. DyStar joins other victims from the consumer services, technology, and manufacturing sectors, indicating a pattern of targeting across various industries and geographic locations, including the United States and Taiwan.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed credential exposure for the dystar.com domain. This included corporate credentials for Microsoft 365 (smtp.office365.com) and an internal training portal, as well as corporate emails reused on third-party sites. A single corporate username appeared in both internal and third-party categories, suggesting a potential compromise of an employee workstation with credential reuse. The exposed data had a freshness window between May 14 and June 28, 2026. Credential harvesting through stealer logs is a common initial access vector for ransomware groups like Settra. While this specific log data doesn’t confirm Settra’s direct use of these credentials, the pattern of exposing corporate credentials tied to potential endpoint compromise aligns with typical ransomware kill chains. CTI teams are advised to prioritize credential rotation, session revocation, and endpoint forensics.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.