UFOC Data Breach

Alleged

Ransomware claim involving UFOC

Published: Aug 19, 2026 Deadlock
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
UFOC
Industry
Government
Threat Actor
Deadlock
Date of Incident
Aug 19, 2026

Executive Summary

The Deadlock ransomware group has claimed UFOC, an organization based in Taiwan, as a victim, listing it on their dark web portal on August 19, 2026. The same day, the group also listed Global Terminal Services, a Turkish company. This incident was identified through SOCRadar’s Dark Web Monitoring service. UFOC’s operations in Taiwan, particularly within sectors that Deadlock has historically targeted, may have made it a suitable candidate for extortion activity. Deadlock has demonstrated a pattern of targeting transportation and industrial entities in the Middle East, while also pursuing government-adjacent organizations across the Asia-Pacific region. Taiwan has been a recurring location for the group’s activities in APAC. The dual targeting of a Taiwanese entity and a Turkish company within close proximity in time aligns with the group’s operational trends, suggesting a consistent approach to victim selection across different geographic and industrial landscapes.

Technical Analysis

SOCRadar’s investigation using stealer-log data queried against ufoc[.]com[.]tw revealed 17 records. These included 7 employee credentials and 10 corporate credential entries. The employee credentials indicated access to Microsoft 365 (login.microsoftonline[.]com), UFOC’s internal webmail (mail.ufoc[.]com[.]tw), and an internal workflow application (workflow.ufoc[.]com[.]tw). Notably, the presence of credentials for on-premises mail and workflow portals is significant, as custom-hosted infrastructure often lacks the robust MFA enforcement found in cloud services, potentially offering a more direct path for network access. The data captured spans from February 2026 to July 22, 2026, indicating a recent compromise window shortly before the listing date. While this stealer-log data does not definitively confirm that Deadlock utilized these specific credentials, the discovery of 17 records affecting both cloud identity and on-premises systems, with a freshness date in July, is highly indicative of the pre-staging phase commonly observed in such ransomware incidents. It is therefore prudent to consider all 17 identified credential records as compromised. Further investigation into the access logs for mail.ufoc[.]com[.]tw and workflow.ufoc[.]com[.]tw for anomalous authentication activity in the weeks preceding August 19 is strongly recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.