SKLG Data Breach

Alleged

Ransomware claim involving SKLG

Published: Sep 28, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
SKLG
Industry
Commercial
Threat Actor
Qilin
Date of Incident
Sep 28, 2026

Executive Summary

Qilin ransomware group listed SKLG, a Japanese company operating under the domain sklg[.]co.jp, on its dark web portal on September 28, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring. SKLG operates within Japan’s industrial and commercial sectors, a profile that aligns well with Qilin’s typical targeting preferences, suggesting potential vulnerabilities in its operations or data that may attract ransomware or extortion activities. Qilin has been a highly active threat actor, claiming 249 other victims in the past 60 days. The group predominantly targets the Manufacturing sector, with Technology and other industrial industries also frequently compromised. While Qilin operates globally, with the US, Germany, and the UK as primary targets, Japan remains a consistent secondary target. SKLG’s inclusion adds to a growing list of Japanese victims, which includes Nissho Electric Manufacturing, IKEGAMI TSUSHINKI COMPANY LIMITED, Mitsuwa Trading Co., Ltd, and ASCII Group. The presence of four Japanese victims within a single 60-day period indicates either a deliberate campaign targeting the region or a strong supply of compromised Japanese corporate access from the underground market.

Technical Analysis

A query against the domain sklg[.]co.jp returned no records in the monitored stealer-log datasets. It is important to note that Japanese business domains often utilize localized email infrastructure and third-party platforms that may not be covered by standard Western stealer-log data feeds. Therefore, a null result from this query does not definitively confirm that the organization is unaffected, and expanded monitoring is recommended. The typical access vector employed by the Qilin ransomware group involves the use of stolen credentials, which are then validated against services such as Microsoft 365 or VPNs. This method is applicable to organizations worldwide, including those in Japan. For SKLG, it is advisable to implement forced credential rotation and enhance dark web monitoring specifically for the sklg[.]co.jp domain to mitigate potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.