Lawter Data Breach

Alleged

Ransomware claim involving Lawter

Published: Sep 1, 2026 MedusaLocker
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Lawter
Industry
Manufacturing
Threat Actor
MedusaLocker
Date of Incident
Sep 1, 2026

Executive Summary

MedusaLocker listed Lawter, a US-based specialty chemicals manufacturer, on its dark web portal on September 1, 2026. SOCRadar Dark Web Monitoring identified this listing. Lawter produces resins and intermediates for the printing, packaging, and coatings industries and operates globally as part of a larger multinational chemical group. The manufacturing sector is often targeted by ransomware groups due to its critical infrastructure role and potential for significant disruption. MedusaLocker has been active since at least 2019 and has claimed 12 other victims in the 60 days preceding this incident. The group primarily targets the Manufacturing, Retail and E-Commerce, and Technology sectors, with a geographic focus on Canada, the United States, and Australia. Recent victims in the manufacturing sector claimed by MedusaLocker include Qualisteel and Bija Industrie, indicating a consistent pattern of targeting organizations within this industry.

Technical Analysis

A stealer-log query for lawter[.]com revealed 25 records spanning from September 2025 to August 2026, with the most recent entry dated August 27, 2026, just five days before the MedusaLocker listing. This query identified both employee credentials and third-party records, suggesting a potential risk of workstation compromise. The findings included 2 employee credentials and 23 third-party records. The compromised credentials were linked to key endpoints including lawter.okta[.]com (Okta SSO identity provider), login.microsoftonline[.]com (Microsoft 365 / Azure AD tenant), and Dropbox. The evidence does not confirm that these specific credentials directly triggered the intrusion, but the five-day gap between the most recent stealer log entry and the ransomware listing suggests they were likely valid at the time of the ransomware deployment. The sequence of fresh Okta credentials appearing in a manufacturing sector stealer log, followed by a ransomware listing within five days, is a common pattern. MedusaLocker affiliates and other ransomware-as-a-service (RaaS) operators often leverage SSO credentials because they facilitate lateral movement across cloud workloads without the need for on-premise exploitation. Compromised Okta or Azure AD tokens can grant access to shared drives, internal systems, and business SaaS environments through a single authentication. Organizations should rotate all Okta, Microsoft 365, and Dropbox credentials immediately and review identity provider logs from August 27, 2026, onward.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.