Neogen Corporation Data Breach

Alleged

shinyhunters claim involving Neogen Corporation

Published: Aug 30, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Neogen Corporation
Industry
Technology
Date of Incident
Aug 30, 2026

Executive Summary

shinyhunters listed Neogen Corporation, a US-based technology company operating at neogen[.]com, on its leak site on 2026-08-30, alleging unauthorized access to the company’s systems and data. The claim has not been independently verified. The company’s presence in the technology sector, particularly in the United States, makes it a potentially attractive target for cybercriminal groups. shinyhunters listed 24 victims over the past 60 days, primarily targeting the US, Israel, and Switzerland, with a sector focus on Technology and Healthcare. Neogen Corporation’s technology profile in the US aligns with the group’s established targeting pattern, suggesting a potential match between the victim’s characteristics and the threat actor’s usual operational activities.

Technical Analysis

SOCRadar CTI’s stealer-log analysis returned a severe exposure in sample verdict for Neogen Corporation. Infostealer telemetry flagged 1 employee Okta SSO credential and 22 external/customer records on org portals with very recent activity. Credential timestamps span 2026-06-09 to 2026-08-27, indicating pre-attack access that nearly coincides with the claimed listing date. A compromised Okta SSO credential combined with 22 external/customer portal records represents significant pre-attack exposure. Active SSO credentials provide direct, stealthy entry into corporate environments and reduce the attack surface shinyhunters would need to exploit externally. Rotate the flagged Okta SSO credential immediately and audit SSO authentication logs for anomalous events from 2026-06-09 forward. Review external portal accounts for unauthorized access and enforce MFA across all customer-facing services.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.