CORBY ROCK MILL Data Breach

Alleged

Ransomware claim involving CORBY ROCK MILL.

Published: Oct 6, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
CORBY ROCK MILL
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Oct 6, 2026

Executive Summary

Qilin ransomware group listed CORBY ROCK MILL on its dark web leak site on October 6, 2026. CORBY ROCK MILL, an Irish manufacturing company operating at corbyrock[.]ie, had eight VPN credentials exposed in stealer logs for over seventeen months prior to this listing. SOCRadar’s Dark Web Monitoring service identified this claim. The manufacturing sector is a known area of focus for the Qilin ransomware operation, making companies within this industry a potential target. In the 60 days leading up to this listing, Qilin claimed 216 other victims, indicating significant operational tempo. Manufacturing and Technology are frequently targeted industries for this group. While the United States, Germany, and the United Kingdom are leading victim countries, European targets like Ireland are also regularly impacted. Notable recent victims in the manufacturing sector include Allied Recycling, Mutsumi Group, Cotesma, and Emser. CORBY ROCK MILL’s inclusion aligns with Qilin’s established targeting patterns.

Technical Analysis

SOCRadar’s telemetry data revealed 8 credential records associated with the corbyrock[.]ie domain. All identified credentials were classified as Category A, indicating employee authentication against organizational systems. These records specifically targeted CORBY ROCK MILL’s VPN gateway and its related user portal. Two distinct patterns of masked usernames were observed across these credentials. The earliest record dates back to February 2025, with the most recent entry from July 2026, indicating an unrotated credential exposure period of seventeen months. The observed credential exposure aligns with Qilin’s typical modus operandi. The group is known to source infostealer-harvested credentials from underground markets, validate their usability against VPN portals, and then provide access to affiliates for further exploitation. The discovery of eight unrotated VPN credentials directly fits this established intrusion chain. While this stealer-log data does not definitively confirm that Qilin utilized these specific credentials for initial network access into CORBY ROCK MILL’s environment, the alignment is highly suggestive. Response teams should consider the identified accounts as potentially compromised. It is recommended to pull VPN access logs and prioritize a thorough review of any sessions occurring between February 2025 and July 2026. Continued monitoring of dark web stealer logs and proactive credential hygiene checks, including password rotation and multi-factor authentication review for VPN and remote access solutions, are advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.