iwin Data Breach

Alleged

Ransomware claim involving iwin.

Published: Sep 1, 2026 Black X
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
iwin
Industry
Financial Services
Threat Actor
Black X
Date of Incident
Sep 1, 2026

Executive Summary

Black X has claimed responsibility for a data breach affecting iwin, a South Korean technology company specializing in digital services and software solutions. The threat was identified when iwin was listed on Black X’s dark web portal on September 1, 2026, a listing flagged by SOCRadar Dark Web Monitoring. As iwin operates within the technology sector in South Korea, it aligns with the typical targets of ransomware groups, potentially due to the valuable data or critical infrastructure it manages. In the preceding 60 days, Black X has claimed responsibility for six other victims. The group’s primary targeting has focused on the Technology, Financial Services, and Manufacturing industries. Geographically, their most frequent targets include South Korea, Yemen, and Vietnam, with South Korea being the most heavily targeted country within this period. This makes iwin’s listing particularly relevant as it falls within Black X’s primary geographic focus. Previous victims identified in South Korea and the technology sector by the group include i-one, FE CREDIT, Tong Kong E & E Sdn Bhd, and sanaa hospital, indicating a pattern of consistent targeting within these segments.

Technical Analysis

A query for stealer-log records associated with the domain iwin[.]kr returned no results within the specifically queried dataset. It is important to note that the absence of records in this particular query does not definitively confirm that the organization is unaffected by credential compromise. The lack of positive signals could be attributed to several factors, including the possibility that compromised credentials exist under alternate corporate domains, use personal email aliases, or reside in data feeds not included in the queried slice. Furthermore, records may have been used and subsequently rotated by the threat actors before the indexing period, or the data may not yet have been fully indexed. Therefore, continued monitoring of the iwin[.]kr domain is recommended to detect any emerging threats or new listings.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.