Quick Summary
AllegedExecutive Summary
Qilin ransomware group listed Ikegami Tsushinki Company Limited on its dark web portal on September 21, 2026. SOCRadar’s Dark Web Monitoring identified this listing. Ikegami Tsushinki Company Limited is a well-established Japanese manufacturer specializing in broadcast imaging and security surveillance systems, with operations serving media, security, and industrial markets globally. The ransomware group has claimed 243 other victims in the past 60 days. The most frequently targeted sectors by Qilin include Manufacturing, Professional Services, and Others, with victims primarily located in the United States, Germany, and the United Kingdom. The inclusion of Ikegami Tsushinki Company Limited, a Japanese entity, is somewhat unusual in Qilin’s typical victimology, which predominantly targets Western markets. While the group has listed victims in the Asia-Pacific region before, such as Mitsuwa Trading Co., Ltd, ASCII Group, and East Field Corporation, the current targeting of a Japanese manufacturer aligns perfectly with Qilin’s established pattern of targeting the manufacturing sector.
Technical Analysis
SOCRadar’s Dark Web Monitoring identified one record associated with yebisu.ikegami[.]co[.]jp, dated August 10, 2026. The username associated with this record is masked, making it difficult to definitively classify whether it belongs to an employee account or an external user. The endpoint itself is confirmed to belong to the victim organization. A single masked record surfaced from a paginated query of Japanese-domain credentials. This finding is classified as low-confidence data. It is important to note that Japanese corporate environments often utilize internal authentication naming conventions that differ from their public website domains. Consequently, a query limited to a single domain may significantly undercount the actual extent of exposed credentials. Continued monitoring across the primary domain ikegami[.]co[.]jp and any known internal endpoint variants is strongly recommended. This vigilance is crucial for detecting any further potential credential exposures or signs of compromise. The limited scope of the current query means that the absence of further evidence does not rule out the possibility of a broader compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.