Namyang Industrial Co., Ltd. Data Breach

Alleged

Ransomware claim involving Namyang Industrial Co., Ltd.

Published: Aug 6, 2026 Barracuda
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Namyang Industrial Co., Ltd.
Industry
Manufacturing
Threat Actor
Barracuda
Date of Incident
Aug 6, 2026

Executive Summary

Namyang Industrial Co., Ltd., operating under the brand NAMYANG NEXMO, is a manufacturing company based in South Korea. The company has been identified as a victim on the dark web portal of the Barracuda ransomware group, with the listing published on August 6, 2026. This discovery was made via SOCRadar’s Dark Web Monitoring service. Namyang Industrial maintains a significant self-managed IT infrastructure, including an identity provider, VPN gateway, and HR systems, all managed under its own domain. This listing marks the company as one of four Barracuda entries published on the same date. In the 60 days preceding this listing, Barracuda claimed three other victims on its leak portal. The group primarily targets the manufacturing, technology, and healthcare sectors, with a notable concentration of victims in China, South Korea, and the United States. Namyang Industrial shares a sector and geographic overlap with previous Barracuda victims such as RS Automation Co Ltd, Micro-Comm Inc, and Ferrell / Skyline Implants & Periodontics. Given its substantial infrastructure and size, Namyang Industrial appears to be the most significant target listed by Barracuda in their recent activity.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the nynexmo.com domain. The queried sample contained a total of twenty-two records, including ten employee credentials on organization-owned systems, five third-party or supplier accounts on those systems, and six corporate identities on external services. These exposed credentials provide access to high-value endpoints such as a Keycloak-based single sign-on provider, the corporate VPN gateway, and both HR and payroll portals, indicating a potential path from the perimeter to sensitive personnel data. One corporate identity was found to recur across ten records spanning five months, with additional employee-ID handles appearing on the VPN and HR systems. The freshness of these records ranges from February 3, 2026, to July 28, 2026, indicating long-term persistence of exposed credentials. This profile strongly suggests a corporate intrusion risk. For ransomware groups like Barracuda, credentials harvested by infostealers are a known method for initial access. Threat actors often source logs from underground marketplaces, validate corporate credentials, and then use them to access systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log data does not definitively confirm that these specific credentials were used by Barracuda, the presence of unrotated federated SSO and VPN credentials for five months presents a textbook scenario for potential compromise. Cybersecurity teams should prioritize rotating credentials across identity, VPN, and HR systems to mitigate this risk, rather than waiting for direct confirmation of an attack.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.