Quick Summary
AllegedExecutive Summary
Storm ransomware listed Allied Machine & Engineering, a U.S.-based precision machining and tooling manufacturer, on its dark web leak site on October 3, 2026. SOCRadar’s stealer-log data revealed a significant credential exposure occurring between July and September 2026. The compromised assets included credentials for UltiPro (now UKG Pro), a human resources and workforce management platform, tied to a single employee account, as well as eleven external user credential records associated with third-party authentication portals used in the organization’s operations. The exposure of UltiPro credentials is of particular concern, as HR platforms typically contain sensitive employee Personally Identifiable Information (PII), compensation details, benefits enrollment records, and organizational hierarchy. This data can be leveraged for targeted social engineering attacks and may necessitate breach notifications under U.S. state privacy laws. Storm has been actively targeting the U.S. manufacturing and industrial engineering sectors for the past 60 days, with affiliates utilizing infostealer-harvested credentials for initial access to cloud identity and SaaS platforms. Their pattern involves moving laterally towards valuable data repositories before deploying encryption. Allied Machine & Engineering’s production of specialized cutting tools and drilling systems for aerospace, automotive, and industrial applications makes its proprietary tooling designs and customer specifications a prime target for extortion.
Technical Analysis
Storm listed Allied Machine & Engineering on its dark web leak site on October 3, 2026. SOCRadar’s analysis of stealer-log data indicated a credential exposure spanning July through September 2026, a three-month period. The compromised data included UltiPro (now UKG Pro) HR and workforce management credentials for one employee account and eleven external user credential records from third-party authentication portals. UltiPro access typically involves sensitive employee PII, compensation information, and benefits enrollment data, which are valuable for targeted social engineering and can trigger breach notification requirements under U.S. privacy laws. The threat actor, Storm, has demonstrated a pattern of targeting U.S. manufacturing and industrial engineering companies over the preceding 60 days. Their operational method involves using credentials obtained from infostealer malware to gain initial access to cloud identity and SaaS platforms. Subsequently, they engage in lateral movement to access high-value data repositories before initiating encryption. Allied Machine & Engineering’s business of manufacturing specialized cutting tools and drilling systems for sectors like aerospace and automotive makes its intellectual property, such as proprietary tooling designs and customer specifications, a particularly attractive target for extortion. Organizations should audit UltiPro/UKG Pro access logs for the July–September 2026 period and immediately revoke all compromised HR platform credentials. It is also crucial to correlate the eleven external portal records with the company’s vendor and partner ecosystem to identify potentially compromised third-party access points. An assessment should be conducted to determine if the employee PII within UltiPro triggers any state-level breach notification obligations. Engaging an incident response firm with specific expertise in the manufacturing sector and experience dealing with Storm intrusions can expedite the scoping and remediation phases, given the group’s consistent lateral movement patterns.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.