WireCo Data Breach

Alleged

Ransomware claim involving WireCo.

Published: Aug 26, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
WireCo
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Aug 26, 2026

Executive Summary

WireCo, a global manufacturer specializing in wire rope, synthetic rope, and high-performance cordage, serving vital industries such as oil and gas, mining, crane, and marine, was listed as a claimed victim on the Qilin ransomware group’s dark web portal on August 26, 2026. This claim was identified through SOCRadar’s Dark Web Monitoring service, though it has not been independently verified. The company’s involvement in foundational industries and its global operational footprint may attract attention from threat actors seeking disruption or financial gain. In the 60 days preceding this listing, Qilin claimed 217 victims, with a strong focus on the Manufacturing, Professional Services, and Technology sectors, predominantly in the United States, Germany, and Italy. WireCo’s inclusion aligns with Qilin’s recent targeting of US industrial manufacturers, including Teikoku USA, Double H Equipment, tommer construction, and B Wright Drywall, reflecting a sustained campaign against these targets throughout the summer of 2026.

Technical Analysis

SOCRadar’s telemetry identified 26 records associated with wireco[.]com, collected between June 12 and August 25, 2026. These records include 19 employee credentials found on target-owned or identity-provider infrastructure, and 4 external-user accounts on WireCo systems, along with 3 unclear records. The concentration of records on the identity provider, specifically auth0.navexone.com, suggests a potential avenue for initial access. The presence of 11 records with @wireco.com credentials on auth0.navexone.com, identified as WireCo’s identity provider, is particularly concerning as it represents a critical access point. Additionally, 6 records were found on changepass.wireco[.]com, with one @wireco.com account appearing multiple times from June through August 2026. This repetitive authentication activity for a single corporate identity on a password-change endpoint over an extended period could indicate an adversary repeatedly testing access or an ongoing issue with credential compromise that has not been fully resolved through password resets. The consistent pattern of repeated access to both the identity provider and the password-change endpoint by the same corporate account over three months serves as a strong pre-compromise signal. This activity is indicative of an adversary potentially maintaining a foothold or validating credentials before attempting lateral movement within the network. While these telemetry findings do not definitively confirm Qilin’s specific method of intrusion, the focus on identity provider credentials is a common tactic employed by ransomware operators. Therefore, the credentials associated with auth0.navexone.com and changepass.wireco[.]com should be treated as urgent remediation priorities. This includes resetting the recurrent account, thoroughly auditing authentication logs across the observed period, and verifying that any credential rotation has effectively resolved the underlying security issue rather than simply cycling compromised credentials.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.