Quick Summary
AllegedExecutive Summary
Namyang Industrial Co., Ltd., a manufacturing company based in South Korea and also known as Namyang NEXMO, was identified as a victim on the Barracuda ransomware group’s leak site on August 23, 2026. The company supplies industrial components and manufacturing solutions to the Korean and broader Asian markets. This listing places a South Korean manufacturer within Barracuda’s typical victimology, which has predominantly focused on the United States and South Korea. In the past 60 days, Barracuda has claimed approximately 8 victims, with Healthcare, Manufacturing, and Professional Services being their most frequently targeted industries. The United States, South Korea, and Brazil are the countries most frequently affected by this group. South Korea’s prominence in Barracuda’s victim profile aligns directly with the reported listing of Namyang Industrial. While other manufacturing targets from South Korea were not immediately apparent in the dataset, the group’s concurrent targeting of US-based healthcare organizations like Clinical Associates of the Finger Lakes and Skyline Implants & Periodontics highlights its ongoing activity across different sectors.
Technical Analysis
SOCRadar’s stealer-log telemetry analysis revealed a “severe_exposure_in_sample” verdict for the domain nynexmo.com, which is associated with Namyang Industrial. The queried sample contained 10 employee credentials on organizational systems, indicative of workstation compromise signals, 5 external user records on organizational infrastructure, and 6 corporate credentials found on third-party platforms. Notably, critical infrastructure such as the organization’s VPN gateway, HR and HRIS portals, and a Keycloak-based identity provider were accessed using corporate credentials. A single corporate email address was observed across 10 records spanning from early February to late July 2026, indicating reuse across identity infrastructure, HR systems, and third-party SaaS applications. This pattern is consistent with unrotated credentials from a compromised workstation or an ongoing infection. The exposed data spans a freshness window from February 3, 2026, to July 28, 2026, highlighting a significant period of potential credential exposure. The observed stealer-log evidence does not definitively confirm that these credentials were used by Barracuda as the initial access vector for the ransomware attack. Stolen credentials can be traded, resold, or independently obtained by various threat actors. However, the credential exposure, predating the ransomware listing by several months and encompassing access to identity and VPN infrastructure, serves as a strong indicator of elevated pre-incident risk. Organizations in similar situations are advised to audit identity logs within the identified freshness window and reset all affected corporate credentials, irrespective of the ransomware attribution.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.