Quick Summary
AllegedExecutive Summary
Genesis Engineering Group, a manufacturing company based in the United States, has been listed as a victim on the Dark Project ransomware group’s dark web portal, with the listing published on August 5, 2026. This was identified through SOCRadar’s Dark Web Monitoring service. The company’s operations in engineering and manufacturing place it within a sector that accounts for the largest share of the Dark Project group’s recent activity. Genesis Engineering Group is among several US industrial firms listed in the same batch of alleged victims. In the 60 days preceding this listing, Dark Project claimed 17 other victims. The group demonstrates a strong targeting pattern within the manufacturing, healthcare, and transportation sectors. Its victims are predominantly located in the United States, the United Kingdom, and the Philippines. Notable recent victims that share a profile with Genesis Engineering Group, being US manufacturing organizations, include Rocky Mount Recyclers, Leviton, Mayco International, and Sutherland Packaging. This consistent targeting of the manufacturing sector by the group highlights a predictable pattern for defenders in this industry.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for the domain geneng.net in the queried slice. It is important to note that a null result does not confirm the organization is unaffected. The query covered a paginated sample rather than the complete data corpus, and alternate or subsidiary domains were not included in the lookup. Furthermore, credentials harvested under personal email aliases would not surface against the corporate domain. Abbreviated corporate domains, in particular, tend to be under-represented when staff authenticate using a longer public-facing domain. For ransomware groups like Dark Project, infostealer-harvested credentials are a well-documented initial access vector. Operators or initial access brokers often source fresh logs from underground marketplaces, validate the corporate credentials, and subsequently use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of evidence in this specific query does not rule out this scenario. Credentials may have surfaced in feeds outside of this dataset, been used and rotated before indexing, or been harvested under personal email aliases. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than interpreting a null query as exoneration. This includes ongoing dark web monitoring, proactive password rotation, multi-factor authentication review, and monitoring of Microsoft 365, VPN, and remote-access activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.