Quick Summary
AllegedExecutive Summary
Midal Cables was targeted by the DragonForce ransomware group, as reported on July 14, 2026. Midal Cables is an industrial manufacturer based in the UAE. This listing was detected by SOCRadar’s Dark Web Monitoring service. Manufacturing is identified as a high-leverage target due to its critical dependencies on operational systems like ERP, making disruption highly impactful. This incident places a Middle Eastern manufacturing firm on DragonForce’s victim list.
Technical Analysis
SOCRadar’s investigation, utilizing stealer-log telemetry, identified a significant credential exposure for midalcable[.]com. The compromised data contained credentials for internal production and ERP application servers, as well as numerous corporate usernames associated with the @midalcable[.]com domain found on various third-party services, including Oracle Cloud Identity and Webex SAML SSO. The prevalence of a single corporate account across both internal and external platforms suggests a heavily compromised employee endpoint. The collected credentials span from early June to mid-July 2026. While the stealer logs do not definitively confirm DragonForce’s direct use of these credentials for the breach, the pattern of corporate logins on internal systems and SSO platforms aligns with the typical kill chain for ransomware attacks. Recommended actions include isolating the compromised endpoint, forcing password resets for all @midalcable[.]com accounts, and implementing Multi-Factor Authentication (MFA) on internal and SSO systems.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.