King International LLC Data Breach

Alleged

Ransomware claim involving King International LLC

Published: Aug 6, 2026 Gammax
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
King International LLC
Industry
Business Services
Threat Actor
Gammax
Date of Incident
Aug 6, 2026

Executive Summary

King International LLC, an organization operating in the United States and categorized outside standard commercial verticals, has been identified as a victim on the Gammax ransomware group’s dark web portal. The listing, published on August 6, 2026, was detected by SOCRadar’s Dark Web Monitoring service. The entity operates under a US-scoped domain, but its specific industry classification was not recorded, limiting a detailed characterization of its operating profile from this dataset alone. This particular listing represents the only Gammax entry published on this specific date. In the 60 days leading up to this listing, Gammax has claimed three additional victims, demonstrating a targeting pattern that spans professional services and the energy and utilities sectors. Geographically, Gammax’s victims are primarily concentrated in the United States, Saudi Arabia, and Colombia. Recent Gammax listings that share a profile overlap with King International LLC include MTCO, AguAseo, and RE/MAX 1st Choice. The group’s activity of four listings in two months is insufficient to establish a definitive pattern, and the geographic spread across three continents suggests opportunistic acquisition of access rather than a focused regional or sector strategy.

Technical Analysis

SOCRadar’s analysis of initial access correlation against its stealer-log telemetry returned no records for the domain kingsinternational.us within the queried sample. It is crucial to note that a null result from this query does not definitively confirm the organization is unaffected. The query covered a paginated sample from a single dataset, and potential exposure through alternate corporate domains, other hosted mail platforms, or the use of personal email aliases on corporate systems would not be identified. Furthermore, the queried domain differs slightly from the organization’s recorded name, introducing the possibility of a namespace mismatch that could have contributed to the null result. For ransomware groups like Gammax, credentials harvested by infostealers represent a well-documented method for initial access. Threat actors or initial access brokers commonly source fresh logs from underground marketplaces, validate the corporate credentials, and subsequently use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. The absence of evidence in this specific query does not preclude this scenario; harvested credentials may have appeared in feeds outside the queried dataset, been used and subsequently rotated before indexing, or been obtained through personal email aliases. Consequently, threat intelligence teams should prioritize continued monitoring and proactive credential hygiene checks rather than interpreting a null query as an indication of security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.