Woodlore International Inc. Data Breach

Alleged

MetaEncryptor ransomware claim involving Woodlore International Inc.

Published: Aug 23, 2026 MetaEncryptor
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Woodlore International Inc.
Industry
Agriculture and Food Production
Threat Actor
MetaEncryptor
Date of Incident
Aug 23, 2026

Executive Summary

Woodlore International Inc., a company operating in Canada, was identified as a victim of the MetaEncryptor ransomware group, with the listing appearing on their leak site on August 23, 2026. The organization operates within the Canadian market. This listing signifies a geographic expansion for MetaEncryptor, adding a Canadian entity to a victimology that primarily consists of organizations from the United States and Japan, especially within the current operational period. In the last 60 days, MetaEncryptor has claimed approximately seven victims, with its most frequently targeted industries being Other, Manufacturing, and Agriculture and Food Production. While the United States and Japan are the group’s leading victim countries, Germany also features prominently. Canada is not among MetaEncryptor’s top three victim geographies. Another victim in the ‘Other’ industry classification, Corona Corporation from Japan, is also documented in the current dataset. Woodlore International’s Canadian location diverges from MetaEncryptor’s typical US-centric targeting but aligns with the group’s documented strategy of pursuing targets of opportunity beyond its primary geographic focus when access is feasible.

Technical Analysis

A correlation against SOCRadar’s stealer-log telemetry for the domain www.woodlore.ca returned no records within the queried sample. It is important to note that a null result does not equate to a confirmed clean security posture. The queried sample was paginated, and there is potential for credentials to exist under alternate corporate domains or be associated with personal email aliases, which fall outside the scope of this specific query. Furthermore, any identified credentials may have been utilized and subsequently rotated before the indexing of the data. Infostealer-harvested credentials are a primary initial access vector for many ransomware operations. While this specific query did not surface evidence linking Woodlore International Inc. to such compromised credentials via stealer logs, the absence of findings in a limited sample is not definitive proof of an absence of compromise. MetaEncryptor’s operational profile is consistent with various entry points, including phishing campaigns, exposed VPN appliances, and the use of recycled credentials. Therefore, it is recommended that affected organizations conduct thorough audits of their authentication logs, enforce multi-factor authentication on all internet-facing services, and treat the ransomware group’s listing as a strong indicator that the threat actor has gathered significant operational intelligence regarding the target.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.