Quick Summary
AllegedExecutive Summary
Greco Steel Products, a steel and metal manufacturer based in Greece, was reportedly targeted by the Settra ransomware group. The incident was identified through SOCRadar’s Dark Web Monitoring, which flagged the company’s inclusion on Settra’s leak site on August 19, 2026. The manufacturing and heavy industry sectors are consistent targets for ransomware operations due to their critical infrastructure, potential for significant operational disruption, and the sensitive nature of their data, making them attractive to threat actors seeking financial gain through extortion. The publication on August 19, 2026, included other entities such as M.A.K. Freight Systems (Malaysia, Transportation), AMBITION Group (Japan), ALPHANUMERIC SYSTEMS, INC. (US), and West Coast Management and Realty. This diverse geographical spread across Southeast Asia, East Asia, North America, and Southern Europe suggests the threat actor is leveraging access obtained through initial access brokers (IABs) rather than conducting a targeted campaign against a specific sector like European manufacturing. This broad targeting pattern is typical of ransomware groups seeking to maximize their victim count and revenue streams.
Technical Analysis
A query for stealer-log records associated with the domain greco-steel[.]gr returned no positive results. It is important to note that this null finding does not confirm that the organization is unaffected. The query encompassed a limited, paginated sample of data, and there is a possibility that credentials may exist in other data feeds not covered by this specific search. Furthermore, credentials could have been compromised and subsequently rotated before they were indexed in the analyzed datasets. It is also possible that credentials were harvested using personal email aliases that were not included in the scope of this query. The absence of direct stealer-log matches does not rule out a potential compromise. Information from infostealer logs can be crucial for ransomware operations, as it often provides threat actors with access credentials for corporate accounts. These credentials can be used to gain entry into victim networks through various means, including Microsoft 365 accounts, VPNs, and other remote-access portals. Such access can then be leveraged for further lateral movement, data exfiltration, and ultimately, ransomware deployment. Therefore, continued monitoring for any potential credential exposure or unusual activity remains recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.