Core Materials Data Breach

Alleged

Ransomware claim involving Core Materials

Published: Aug 30, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Core Materials
Industry
Manufacturing
Threat Actor
Chaos
Date of Incident
Aug 30, 2026

Executive Summary

The ransomware group chaos has claimed Core Materials, a US-based manufacturing company operating with the domain corematerials[.]com, as a victim. The claim was published on August 30, 2026. This incident is highlighted by the discovery of a single privileged account credential captured on an internal scanning subdomain, matsmcscan, on September 13, 2025. The presence of a credential within an internal scanning subdomain suggests that the threat actor gained access to the internal network well before the claimed listing date. As of the report’s publication, no independent verification of these claims has been conducted. Within the last 60 days leading up to this report, chaos has claimed 18 victims. The group’s primary geographic targets have been the United States and the United Kingdom, with a strong focus on the Healthcare and Technology sectors. The targeting of Core Materials, a manufacturing entity in the US, indicates that chaos is expanding its operational scope beyond its typical industry focus. The group appears to maintain a moderate operational tempo with a distinct, albeit expanding, victim profile.

Technical Analysis

SOCRadar CTI’s analysis of stealer-log data has indicated a severe exposure for Core Materials. Specifically, a privileged account credential associated with an internal scanning subdomain, matsmcscan, was captured on September 13, 2025. The presence of credentials within an internal scanning subdomain is significant, as these are typically used for asset enumeration and can signify deep network access. Such a credential could substantially reduce the dwell time for a threat actor and facilitate covert staging activities prior to the deployment of ransomware. The capture of a privileged account credential on an internal subdomain is a critical indicator for potential intrusion pathways. Internal scanning subdomains often house administrative tools or access points that, if compromised, could provide threat actors with elevated privileges. This allows for easier lateral movement across the network, reconnaissance, and the potential exfiltration of sensitive data, all of which are precursors to a ransomware attack. The dated credential suggests that the initial compromise may have occurred some time before the ransomware group made its claim public. The data indicates a need for continued dark web and stealer-log monitoring for Core Materials. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for all accounts, are strongly recommended. Furthermore, organizations should scrutinize activity logs for Microsoft 365, VPNs, and other remote-access portals to detect any anomalous behavior that may indicate unauthorized access. Monitoring of alternate corporate domains is also advised to ensure comprehensive coverage.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.