Quick Summary
AllegedExecutive Summary
Leviton, a manufacturing company based in the United States, has been listed as a victim on the Dark Project ransomware group’s dark web portal, published on August 5, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the electrical products manufacturing sector, with the dealer and distributor relationships typical of that market. It is among the larger names in Dark Project’s recent listing population. In the 60 days prior to this listing, Dark Project has claimed 17 other victims across its leak portal. The group has shown a strong targeting pattern in the manufacturing, healthcare, and transportation sectors. Geographically, its victims are concentrated in the United States, the United Kingdom, and the Philippines. Other recent Dark Project listings that overlap with Leviton’s profile — US manufacturing organisations — include Rocky Mount Recyclers, Mayco International, Genesis Engineering Group, and Sutherland Packaging. Leviton is a considerably larger organisation than most of that group, so while the sector fit is exact, the scale is not typical of the group’s usual selection.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the leviton.com domain. All 25 records in the returned sample targeted Leviton subdomains — customer, community, dealer, and store portals — rather than internal identity or mail infrastructure. The usernames in the slice are predominantly generic handles and consumer email addresses, which places the bulk of this exposure in the customer account takeover category rather than employee credential compromise. Portal credentials of this kind still matter for dealer and partner fraud, but they are a weaker indicator of corporate intrusion than identity-provider records would be. For ransomware groups such as Dark Project, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The stealer-log evidence here does not confirm that these credentials were used by Dark Project, and the customer-portal skew means this particular sample is not strong support for that route. CTI teams should treat the finding as evidence of ongoing credential leakage around the organisation’s public-facing estate, and continue monitoring for employee-level exposure that a paginated sample of this shape would not necessarily surface.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.