KINGSSON Data Breach

Alleged

Ransomware claim involving KINGSSON

Published: Aug 4, 2026 Orova
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
KINGSSON
Threat Actor
Orova
Date of Incident
Aug 4, 2026

Executive Summary

Orova ransomware named KINGSSON as a victim on its leak site on August 4, 2026. This listing marked the beginning of the group’s visible activity and was part of a notable cluster of Taiwanese companies targeted. SOCRadar’s Dark Web Monitoring identified this listing. For any organization, such a listing immediately raises concerns about data exposure and the necessity of breach notifications. KINGSSON is identified as being based in Taiwan, with its specific industry sector not yet confirmed. The August 4th listing included 23 other victims claimed by Orova in the preceding 60 days, suggesting this was an early phase of the group’s operations rather than a mature, ongoing campaign. The targeted industries predominantly appear to be healthcare, manufacturing, and financial services, though many victims were listed without a specific industry designation. The victim concentration for Orova has been observed in the United States, Hong Kong, and Taiwan. KINGSSON was listed alongside three other Taiwanese companies: Ultra Fame, DBM Reflex, and EMPYREAN INT’L TECHNO DEVICES, and Global Friction Products, Inc., indicating a focused regional effort that might suggest a shared upstream access source, such as a common supplier, broker, or a similarly exposed technology.

Technical Analysis

A review of SOCRadar’s stealer-log telemetry, which tracks credentials harvested by infostealer malware from compromised endpoints, found no records associated with the domain kingsson[.]com[.]tw in the sampled data. This absence of readily identifiable credential exposure in the sampled data is a positive indicator, but it does not constitute a definitive confirmation that the organization is unaffected. The telemetry query operates on a paginated sample of a substantially larger dataset. It is possible for credentials to exist under alternate corporate domains, legacy domains, or via regional subsidiaries. Furthermore, compromised credentials might be associated with staff personal email aliases or may have been used and subsequently rotated before being indexed. Therefore, the result of “no_exposure_in_sample” means the domain remains on watch. Infostealer-harvested credentials are a common initial access vector for ransomware groups like Orova. Threat actors or access brokers frequently purchase these logs, validate the corporate credentials, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals. This access is then leveraged to deploy ransomware. Given this prevalent attack pathway, it is advisable for KINGSSON to maintain continuous monitoring of the kingsson[.]com[.]tw domain and to proactively conduct credential hygiene checks. This proactive approach is recommended over waiting for definitive evidence of a confirmed breach.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.