Glasfloss Data Breach

Alleged

Ransomware claim involving Glasfloss.

Published: Sep 14, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Glasfloss
Industry
Healthcare
Threat Actor
Chaos
Date of Incident
Sep 14, 2026

Executive Summary

Glasfloss, a manufacturing company based in the United States, was added to the Chaos ransomware group’s leak portal on September 14, 2026. This listing occurred on the same day as another US manufacturing entity, Steelhaus Inc., was also listed, suggesting a pattern of targeted activity rather than a random attack. SOCRadar’s Dark Web Monitoring service identified this listing. The company’s sector and publicly visible security infrastructure may have made it an attractive target for ransomware operations. In the 60 days preceding this listing, Chaos claimed 19 other victims. The group’s primary targets are manufacturing, healthcare, and unclassified sectors. Their activity predominantly focuses on organizations in the United States, United Kingdom, and Australia. Previous victims exhibiting a similar profile to Glasfloss include Steelhaus Inc., ArtiFlex Manufacturing LLC, Core Materials, and Cope Plastics, all of which are mid-market entities with seemingly limited public security infrastructure, aligning with Glasfloss’s characteristics.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for glasfloss[.]com revealed two records. Both records contained corporate email addresses associated with @glasfloss[.]com that were logged against third-party URLs. This pattern is consistent with workstation compromise, indicating that credentials may have been harvested from infected machines. The freshness window for these credentials was between February and June 2026, placing the observed credential activity approximately two to seven months prior to the September 14 listing. The profile associated with this telemetry suggests a risk of workstation compromise. While two credential records represent a small sample size, the telemetry provides a clear signal. The records map to @glasfloss[.]com addresses exposed on external service URLs, distinct from Glasfloss’s own internal systems. This is characteristic of malware-based credential harvesting from workstations rather than a direct breach of Glasfloss’s core infrastructure. The February–June 2026 freshness window for these credentials aligns with the typical dwell time observed before ransomware deployment, often occurring in the late summer months. For ransomware groups like Chaos, credentials harvested via infostealers are a known vector for network intrusion. Threat actors and access brokers often validate these stolen credentials against services such as Microsoft 365, VPN portals, or remote desktop protocol (RDP) access points. Once validated, this access can be sold or passed to ransomware operators for network infiltration. The observed credential activity period from February to June 2026 is consistent with the typical timeline of initial access and potential dwell time leading up to a successful ransomware deployment. Both affected @glasfloss[.]com accounts should be considered compromised. Recommended immediate actions include a password reset for these accounts, a thorough review of multi-factor authentication (MFA) configurations, and an audit of authentication logs from February to June 2026. This review should specifically look for evidence of lateral movement or unusual session activity that may indicate further compromise or reconnaissance by the threat actor. Continued dark web monitoring is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.