FBC Data Breach

Alleged

Ransomware claim involving FBC

Published: Aug 24, 2026 Deadlock
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
FBC
Industry
Business Services
Threat Actor
Deadlock
Date of Incident
Aug 24, 2026

Executive Summary

FBC, a business operating in South Africa under the domain furnbed[.]co[.]za, believed to be involved in furniture or home goods retail, was identified on Deadlock’s leak site on August 24, 2026. This incident marks an extension of Deadlock’s operational reach into the African continent, moving beyond its typical concentration in Europe. The targeting of a South Africa-based entity indicates a potential expansion of the ransomware group’s geographical scope. In the 60 days preceding this listing, Deadlock claimed responsibility for 23 victims, with Manufacturing and Technology sectors being their most frequently targeted. Geographically, their primary focus has been Turkey, Italy, and the UK. The inclusion of FBC in South Africa represents a deviation from this established pattern, suggesting Deadlock is actively broadening its targeting strategy. Other recent victims attributed to Deadlock include UFOC, SHAHEEN LAW GROUP PLC, JP Molyneux Studio, and Global Terminal Services.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not return any records for furnbed[.]co[.]za within the queried data sample. It is important to note that this dataset represents a paginated sample and does not encompass all active log feeds, potential alternate corporate domains, or credentials that may have been harvested using personal email addresses. Therefore, a null result from this specific query should not be interpreted as confirmation that the organization is unaffected by credential compromise. For ransomware groups like Deadlock, initial access brokers (IABs) commonly acquire updated credential logs from underground marketplaces. These credentials are then validated against corporate accounts, including those for Microsoft 365, VPNs, and remote-access portals, before ransomware deployment. Small and medium-sized businesses in South Africa often utilize hybrid infrastructure, combining on-premise and cloud services. This setup can lead to a dispersal of exposed credentials across various systems that may not share unified log feeds, a factor that should be considered during any security hygiene assessment. The observed lack of telemetry does not rule out the possibility of a compromise via alternative means or through unmonitored access vectors. The continued monitoring of dark web marketplaces and stealer logs is recommended to detect any future mentions or activities related to FBC. Proactive credential hygiene checks, including password rotation and multi-factor authentication review, are also crucial. Organizations should also review activity on Microsoft 365, VPNs, and other remote-access portals for any anomalous behavior.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.