Quick Summary
AllegedExecutive Summary
DIATER, a manufacturing company based in Spain, has been targeted by the Deadlock ransomware group. The threat actor added DIATER to its leak portal on July 28, 2026, a discovery flagged by SOCRadar’s Dark Web Monitoring. This incident aligns with Deadlock’s typical targeting pattern, which frequently includes manufacturing entities, particularly those operating in Southern European countries like Spain. The Deadlock ransomware group has been highly active, claiming approximately 25 victims within the past 60 days. Their operations commonly affect the manufacturing sector, alongside general or uncategorized industries and healthcare. Geographically, Deadlock has shown a preference for targeting organizations in Italy, Spain, and Chile. DIATER’s listing fits precisely within this pattern, as Spain is a leading country targeted by the group, and manufacturing is a primary sector of interest. This incident follows similar attacks on other manufacturing companies, including Vinilon, Carrier AB, KEMEK, and HİDROMEK.
Technical Analysis
A review of stealer-log data concerning the domain diater[.]com revealed five records. These records were identified across the primary domain and its internal subdomains. At least one of these records represents a confirmed corporate email credential, while the remaining are of probable corporate use, though they have not been definitively confirmed as such. This activity indicates a risk of corporate intrusion. The identified records span from mid-2025 to April 2026, with recurring usernames observed across different endpoints and a notable lack of credential rotation. While the presence of these credentials does not definitively confirm that DIATER was compromised by the Deadlock ransomware, the unrotated corporate logins, evidenced by their prolonged presence across internal systems, create an ideal entry point for attacks like those orchestrated by Deadlock. Threat actors often leverage such exposed credentials obtained from infostealer logs to gain initial access through methods such as compromising Microsoft 365 accounts, VPNs, or remote-access portals, before deploying ransomware. Given the findings, it is recommended that DIATER implement immediate security enhancements. This includes rotating the credentials associated with the affected accounts and conducting a thorough audit of access to the identified subdomains. Continuous monitoring of the dark web and stealer-log feeds is also advised, as the five discovered records represent a minimum number, and further activity may be present.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.