Quick Summary
AllegedExecutive Summary
WOOSHIN SAFETY SYSTEMS, a South Korean manufacturer of industrial safety systems, was listed on The Gentlemen ransomware group’s dark web leak site on October 3, 2026. The group claims to have exfiltrated sensitive corporate data during the intrusion. The company, operating with the domain wooshinsys[.]co[.]kr, is part of the manufacturing sector, an area that has seen increased attention from both financially motivated ransomware groups and state-sponsored actors in recent years. The nature of its products and operations may attract actors seeking sensitive intellectual property or disruption capabilities. The Gentlemen ransomware group has been actively targeting industrial and manufacturing organizations over the past 60 days. Their typical modus operandi involves affiliates using stolen credentials to gain initial access to corporate IT environments, staging exfiltrated data before deploying ransomware. Korean industrial manufacturers, specifically, have been a notable focus for various threat actors over the last two years, highlighting the region’s significance in the global industrial landscape and its potential as a target.
Technical Analysis
SOCRadar’s stealer-log data revealed credential exposure for WOOSHIN SAFETY SYSTEMS spanning approximately 30 months, from March 2024 through September 2026. The compromised records include credentials for the company’s gateway authentication endpoint, gwa[.]wooshinsys[.]co[.]kr, and for Box cloud storage. The observed employee accounts used numeric identifiers, which appear consistent with internal numbering systems, suggesting a systematic compromise of the authentication infrastructure rather than isolated credential theft. The extended exposure window of 30 months in stealer markets indicates that multiple threat actors may have had access to this data before it was leveraged by The Gentlemen. The extensive exposure window is a significant concern. Compromised gateway authentication credentials can grant access to internal network resources beyond what cloud-only access typically permits. For an industrial safety systems manufacturer like WOOSHIN SAFETY SYSTEMS, the compromise of Box cloud storage could lead to the exposure of sensitive information such as proprietary product designs, engineering specifications, and client installation data. This dual exposure—internal authentication infrastructure and cloud storage over a period of two and a half years—presents a serious pre-positioning scenario for threat actors. Assessment: The prolonged exposure window of 30 months for gateway authentication and Box cloud storage credentials presents a significant risk. These credentials could allow unauthorized access to sensitive corporate data, including proprietary product designs and client information. The combination of access to internal authentication systems and cloud storage, available in underground markets for such an extended period, indicates a substantial pre-incident threat landscape for WOOSHIN SAFETY SYSTEMS. Next Steps: It is recommended that WOOSHIN SAFETY SYSTEMS audit their gateway authentication logs for the entire March 2024–September 2026 period. All Box credentials should be revoked, and a comprehensive access audit for this same timeframe should be conducted to identify any unauthorized downloads or sharing activity. The company should assess the extent to which its industrial client data or product intellectual property was accessible through the compromised accounts. Engaging with KISA (Korea Internet & Security Agency) for incident response support is advisable. Additionally, a review of compliance with the Personal Information Protection Act (PIPA) is necessary if any personal data was involved in the exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.