Metal Conversions Data Breach

Alleged

Ransomware claim involving Metal Conversions.

Published: Aug 26, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Metal Conversions
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Aug 26, 2026

Executive Summary

Metal Conversions, a metal recycling and conversion company based in the United Kingdom, has been listed as a victim by the Qilin ransomware group. The listing appeared on Qilin’s dark web portal on August 26, 2026, as identified by SOCRadar’s Dark Web Monitoring service. While the listing is alleged and has not been independently verified, companies in the manufacturing sector, particularly in Europe, have been a consistent target for the Qilin ransomware group. This incident aligns with a broader pattern of Qilin’s targeting of industrial firms. In the 60 days preceding this listing, Qilin claimed 217 victims. The group primarily targets the Manufacturing, Professional Services, and Technology sectors, with the United States, Germany, and Italy being their most frequent victim countries. Metal Conversions’ listing follows recent claims against other European industrial entities, including Filtronic, Dynamic Laser Solutions Ltd., SC PaderTeG Cabluri Electrice, and Black Cat Engineering & Construction WLL. This ongoing focus on European industrial targets suggests a strategic approach rather than opportunistic attacks.

Technical Analysis

SOCRadar’s stealer-log telemetry returned no records for the domain metalconversions[.]com within the queried sample. It is important to note that this absence of direct correlation does not confirm that the organization is unaffected. The query covered only a paginated and limited sample of indexed logs, and credentials may exist in other data feeds outside this specific dataset. Additionally, exposure could occur under alternate corporate domain variations or be linked to employee personal email aliases, which are not captured in this particular search. For the Qilin ransomware group, stealer-harvested credentials are a documented method for initial access. Threat actors often acquire these credentials from underground markets, validate them for corporate account access, and then use them to authenticate against systems such as Microsoft 365, VPNs, or other remote-access portals. This process typically precedes the deployment of their ransomware. Therefore, the lack of observed stealer-log records for metalconversions[.]com does not rule out this potential intrusion scenario. Organizations are advised to continue monitoring for metalconversions[.]com across additional data feeds and to implement rigorous credential hygiene checks. This includes regular password rotation and thorough review of multi-factor authentication configurations, as well as diligent monitoring of Microsoft 365, VPN, and other remote-access activity logs.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.