i-one Data Breach

Alleged

Black X claim involving i-one

Published: Aug 30, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
i-one
Industry
Financial Services
Date of Incident
Aug 30, 2026

Executive Summary

On August 30, 2026, the Black X extortion group added i-one.co.kr to its leak site, identifying the South Korean technology firm as its latest victim. This listing follows a recent, geographically diverse pattern of attacks by the group, with previous claimed victims located in Yemen and Vietnam. While SOCRadar has identified this listing, there has been no independent verification of the breach claim at this time. The nature of i-one’s operations within the technology sector may make it an attractive target for cybercriminals seeking sensitive data or disruption. Black X has been operating at a low volume, claiming five victims over the past 60 days. These victims were primarily located in Yemen, South Korea, and Vietnam, with the group’s most frequent targets falling within the Financial Services, Manufacturing, and Healthcare industries. The inclusion of i-one, a technology firm, deviates slightly from Black X’s typical sector focus, suggesting either an expansion of their targeting or a less pattern-driven approach in this instance. This specific victim listing extends the known pattern of the group’s activity rather than confirming a strictly established trend.

Technical Analysis

SOCRadar’s analysis of infostealer datasets did not reveal any credential records directly associated with i-one.co.kr. It is important to note that a null result from this specific dataset does not equate to a confirmation that the organization is unaffected by compromise. The absence of evidence in current infostealer logs does not rule out the possibility of credential exposure through other means or that such data has not yet been indexed by the analyzed feeds. This lack of direct telemetry underscores the importance of ongoing monitoring and proactive security measures. Phishing campaigns and the exploitation of publicly accessible services remain plausible initial access vectors that could lead to a compromise, even if direct stealer-log evidence is not immediately apparent. Organizations should maintain vigilance and consider the broader landscape of potential threats that could result in credential compromise and subsequent data exfiltration or ransomware deployment. Continuous monitoring of dark web forums and infostealer logs, coupled with proactive credential hygiene checks, password rotations, and multi-factor authentication reviews for services like Microsoft 365, VPNs, and remote-access portals, are recommended actions to mitigate potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.