ST Engineering Data Breach

Alleged

Ransomware claim involving ST Engineering

Published: Sep 7, 2026 MetaEncryptor
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ST Engineering
Industry
Aerospace
Threat Actor
MetaEncryptor
Date of Incident
Sep 7, 2026

Executive Summary

metaencryptor listed ST Engineering on its dark web portal on September 7, 2026, as identified through SOCRadar’s Dark Web Monitoring. ST Engineering is a multinational defense and engineering group based in Singapore, offering solutions across aerospace, smart city infrastructure, and defense systems, with operations extending across multiple continents. This listing represents a notable expansion of metaencryptor’s targeting into the government and defense sector, an area that has not been a primary focus for the group in its recent victimology. In the past 60 days, metaencryptor claimed 10 other victims across the Healthcare, Manufacturing, and Other sectors, with a concentration in the United States, Canada, and Singapore. Recent listings that share geographic or sector proximity to ST Engineering include Hologic Inc., SIFCO Industries INC., EllisDon Corporation, and FactoryFive. The inclusion of ST Engineering marks the group’s most significant venture into public-sector and dual-use defense infrastructure to date.

Technical Analysis

SOCRadar’s stealer-log telemetry returned zero records for stenng[.]com within the queried dataset. It is important to note that these datasets are paginated and sampled; therefore, a null result does not definitively rule out credential exposure. Credentials may still exist under alternate corporate domains, associated with personal email aliases, or reside in feeds outside the scope of this specific query. Infostealer-harvested credentials are a documented initial-access vector utilized by metaencryptor operators and their affiliated initial-access brokers. The ST Engineering listing represents the highest-profile victim within metaencryptor’s current 60-day operational window. The group’s established pattern of targeting organizations in Singapore, coupled with the nature of ST Engineering’s operations in the dual-use defense sector, elevates this listing beyond a typical ransomware incident. While the null stealer-log result limits definitive conclusions about the initial access method, it does not diminish the priority for continued monitoring. Reviewing access logs for ST Engineering’s infrastructure associated with stenng[.]com and actively monitoring for additional indicators linked to this specific listing are the immediate priorities. Given the context of the defense sector, it is advisable to promptly evaluate stakeholder notification obligations and government reporting requirements.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.