Rocky Mount Recyclers Data Breach

Alleged

Ransomware claim involving Rocky Mount Recyclers

Published: Aug 5, 2026 Dark Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Rocky Mount Recyclers
Industry
Manufacturing
Threat Actor
Dark Project
Date of Incident
Aug 5, 2026

Executive Summary

Rocky Mount Recyclers, a manufacturing company based in the United States, has been listed as a victim on the Dark Project ransomware group’s dark web portal, with the listing published on August 5, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the manufacturing and materials-processing sector, which represents the largest segment of Dark Project’s recent victimology, indicating that Rocky Mount Recyclers’ profile aligns closely with the group’s established targeting patterns. In the 60 days preceding this listing, Dark Project claimed 17 other victims. The group predominantly targets the manufacturing, healthcare, and transportation sectors, with a significant concentration of victims in the United States, the United Kingdom, and the Philippines. Other US manufacturing organizations recently listed by Dark Project include Leviton, Mayco International, Genesis Engineering Group, and Sutherland Packaging, suggesting a current focus on US industrial firms within the mid-market segment.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry related to initial access for rmrnc.com yielded no records within the queried dataset. It is crucial to note that a null result does not definitively confirm the absence of a compromise. The query covered a paginated sample, potentially excluding a complete corpus of data. Additionally, credentials harvested using personal email aliases would not surface against the corporate domain, and credentials linked to short or abbreviated corporate domains may be under-represented if staff commonly use longer marketing domains for authentication. For ransomware groups like Dark Project, infostealer-harvested credentials are a well-established initial access vector. Threat actors or initial access brokers often source current credential logs from underground marketplaces, validate corporate access details, and subsequently use them to gain entry to platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of evidence in this specific query does not negate this possibility; credentials may exist in data feeds outside the analyzed dataset, could have been used and rotated prior to indexing, or were harvested under different corporate domain structures. Given the nature of Dark Project’s operations and the potential for credential harvesting, CTI teams should prioritize ongoing dark web monitoring and proactive credential hygiene checks. Rather than interpreting a null query as exoneration, it is advisable to assume that credentials may have been exposed. Recommended actions include continuous monitoring of stealer-log feeds, conducting thorough credential hygiene reviews, rotating passwords, verifying multi-factor authentication configurations, and actively monitoring alternative corporate domains and access logs for Microsoft 365, VPNs, and remote-access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.