Textile City Data Breach

Alleged

Ransomware claim involving Textile City

Published: Sep 22, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Textile City
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Sep 22, 2026

Executive Summary

On September 22, 2026, the Qilin ransomware group added Textile City to its leak portal, claiming it had compromised the Canadian textile manufacturer. Evidence from stealer logs indicates that employee credentials for Textile City were in circulation for approximately six months prior to the listing, with activity dating back to March 2026. Textile City operates within the manufacturing sector, producing and distributing textiles across North America, a segment frequently targeted by ransomware actors due to its critical infrastructure and potential for significant operational disruption. Qilin has been identified as the most active ransomware group in the preceding 60 days, claiming a total of 248 victims during this period. The group’s operations primarily target the United States, Germany, and the United Kingdom, with a strong focus on the Manufacturing industry. Recent victims listed by Qilin in North America include Service d’usinage 9002, Ceragres, and RoadEx America. Textile City, as a Canadian manufacturer, aligns with the group’s established targeting patterns, indicating a typical victim profile.

Technical Analysis

SOCRadar’s telemetry detected a significant exposure of credentials related to textilecity[.]ca. Specifically, nine employee credentials were found on organizational systems, five customer or third-party records were identified on company infrastructure, and six corporate credentials were found on third-party SaaS platforms. This data spans from March 2026 up to September 14, 2026. The analysis indicates a mixed profile of credentials, with at least one employee account appearing in multiple captures over a six-month period without any observable evidence of credential rotation. The compromised endpoints include critical services such as login.microsoftonline[.]com (for Microsoft 365 identity management), smtp.office365[.]com (for email infrastructure), auth.services.adobe[.]com, and the WordPress administrative console located at textilecity[.]ca/wp-login.php. The prolonged exposure of Microsoft 365 and SMTP access, unrotated for months, represents a prime entry point for ransomware operations. This extended period of vulnerability suggests a high potential for unauthorized access and subsequent malicious activities. The findings necessitate immediate and comprehensive security measures. Organizations should prioritize rotating all exposed credentials, with a particular emphasis on Microsoft 365 and SMTP accounts. A thorough review of sign-in logs from login.microsoftonline[.]com, dating back to the earliest observed compromised activity in March 2026, is crucial to identify any anomalous access patterns or unauthorized sessions. Furthermore, examining the WordPress admin console for suspicious activity is recommended, given the six-month persistence window, which indicates ample opportunity for lateral movement within the network.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.