Quick Summary
AllegedExecutive Summary
Malaysian pewter manufacturer Royal Selangor, an internationally known luxury brand, was listed by the BYOD ransomware group on its dark web leak site on October 5, 2026. Ransomware actors often target companies that possess a combination of reputational leverage, valuable customer data, and e-commerce infrastructure, making Royal Selangor a potential target. The presence of significant stealer log data suggests a plausible entry vector for the attackers. BYOD has claimed 3 victims in the past 60 days, targeting the manufacturing and technology sectors in both Malaysia and the United States, indicating the group’s cross-regional operational scope. Royal Selangor and Trump Mobile Wireless are among these recent claims. This targeting pattern suggests BYOD does not exclusively focus on one market, but rather on industries providing significant leverage for extortion.
Technical Analysis
SOCRadar’s threat intelligence platform identified 16 compromised credential records associated with the domain royalselangor[.]com, spanning the period from July to October 2026. The detected records include one corporate credential log, eleven business application credentials, three workstation compromise artifacts, and one URL-based credential. This exposure indicates a significant risk to the organization’s data and systems. The eleven business application credentials are particularly concerning as they likely grant access to systems crucial for Royal Selangor’s e-commerce operations, customer databases, CRM platforms, and other enterprise systems. Attackers obtaining such credentials can authenticate into cloud services and internal portals, potentially bypassing traditional perimeter defenses and leaving fewer traces compared to methods like brute-force attacks, until the ransomware deployment stage. For a company with international retail operations and a customer-facing digital presence, this credential exposure profile serves as a direct indicator of a potential breach. All active sessions associated with these compromised credentials should be terminated immediately. Customer data, including purchase history, account details, and contact information, must be treated as potentially accessed until forensic analysis can definitively confirm or deny unauthorized access. E-commerce and CRM systems should be prioritized in the scope of forensic investigations to understand the extent of the compromise and the methods used by the threat actors.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.