Onsemi Data Breach

Alleged

Ransomware claim involving Onsemi.

Published: Oct 5, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Onsemi
Industry
Semiconductors
Threat Actor
Qilin
Date of Incident
Oct 5, 2026

Executive Summary

On October 5, 2026, the ransomware group qilin claimed Onsemi (ON Semiconductor), a US-based semiconductor company specializing in power management and signal processing chips with a global supply chain presence, as a victim. This listing was accompanied by a notable observation: all 16 stealer log records SOCRadar identified for the domain onsemi[.]com were dated between October 3 and October 5, 2026. This tight timeframe, spanning just 72 hours immediately preceding the qilin listing, suggests that the credential harvesting occurred concurrently with or just before the active intrusion, rather than as part of a prolonged reconnaissance phase. This distinct pattern shifts the typical threat model associated with such incidents. qilin has demonstrated significant operational scale, claiming 218 victims in the past 60 days. Their activity spans across manufacturing, technology, and other sectors, with a primary focus on targets in the United States, Germany, and the United Kingdom. Notable recent victims include Revenga Smart Solutions, Island, Inkript, and Columbus Informatica. This extensive reach indicates a sophisticated affiliate network actively targeting high-value organizations globally. The incident involving Onsemi aligns with qilin’s pattern of impacting technology companies, particularly within the critical semiconductor industry.

Technical Analysis

SOCRadar’s analysis uncovered 16 compromised records associated with the onsemi[.]com domain. These records were categorized as one corporate credential log, thirteen business application credentials, one workstation artifact, and one URL-based credential. Crucially, all these findings were dated between October 3 and October 5, 2026, coinciding precisely with the timeframe of the alleged intrusion and immediately preceding the ransomware group’s listing. The majority of the exposed credentials, thirteen out of sixteen, were identified as business application credentials. For a publicly traded entity like Onsemi, these credentials likely grant access to a wide array of critical systems, including enterprise SaaS platforms, internal corporate portals, customer-facing systems, and supply chain management tools. The acquisition of such a volume of credentials in bulk, particularly during an active intrusion window, can enable threat actors to rapidly map authentication structures, identify privilege escalation pathways, and advance their attack before a defensive response can be effectively mounted. Given the timing of the credential exposure, it is imperative that all active sessions associated with credentials utilized between October 3 and October 5, 2026, be treated as compromised. Organizations should immediately revoke these sessions and initiate a comprehensive review of all associated accounts. As a publicly traded company, Onsemi may be subject to SEC disclosure requirements depending on the material impact of the incident on its operations or data. A thorough forensic investigation is essential to determine the extent of any accessed supply chain or customer data.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.