Quick Summary
AllegedExecutive Summary
Akira ransomware claimed Coe Press Equipment as a victim, listing the US-based manufacturer on its dark web portal on September 22, 2026. Coe Press Equipment specializes in metal stamping and press automation equipment, serving the industrial sector. This listing was identified through SOCRadar’s Dark Web Monitoring service. The company’s focus on industrial manufacturing makes it a potential target for ransomware groups like Akira, which frequently targets similar sectors. Over the preceding 60 days, Akira reported claiming 62 other victims, positioning itself as one of the most active ransomware groups during that period. Their primary targets are consistently within the Manufacturing, Professional Services, and Other industries, with a strong concentration in the United States, Germany, and the United Kingdom. Notable recent victims in the US manufacturing sector include Anderson Industries, Eagle Construction, Kyodo USA, and PennFab. Coe Press Equipment aligns with Akira’s typical victim profile, representing a mid-market North American industrial firm.
Technical Analysis
A stealer-log query conducted by SOCRadar for the domain coepress[.]com returned no records within the examined dataset slice. It is important to note that this query is bounded and paginated, meaning that credentials may exist under alternate corporate domains or via personal email aliases that were not captured in this specific search. The absence of evidence in this limited query does not confirm that the organization is unaffected by credential compromise. Therefore, while this specific stealer-log search did not yield direct evidence of compromised credentials for Coe Press Equipment, it does not rule out the possibility of such a compromise. Infostealer malware is a common method for threat actors to acquire credentials, which can then be leveraged for initial access into victim networks, potentially leading to ransomware deployment. Organizations are strongly advised to maintain robust credential hygiene practices, including regular password rotation and multi-factor authentication reviews, regardless of the findings from specific monitoring queries. Continued dark web and stealer-log monitoring is recommended. Proactive credential hygiene checks, password rotation, multi-factor authentication review, and monitoring of alternate corporate domains should be considered essential security measures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.