Newman Tractor Data Breach

Alleged

Ransomware claim involving Newman Tractor

Published: Sep 21, 2026 ThreeAM
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Newman Tractor
Industry
Manufacturing
Threat Actor
ThreeAM
Date of Incident
Sep 21, 2026

Executive Summary

Newman Tractor, a US-based company operating in the manufacturing sector, was listed by the threat actor threeam on September 21, 2026. SOCRadar’s Dark Web Monitoring identified this listing. The company deals with agricultural and construction equipment. The presence of ADFS credentials in a stealer-log sample, even if not directly linked to this specific intrusion, is a significant finding due to the critical nature of ADFS for authentication across an organization’s systems. In the preceding 60 days, threeam claimed three other victims: Club One Casino, Twin States News, and Mecasem. These victims spanned the manufacturing, hospitality, and unclassified sectors, primarily located in the United States, Moldova, and Mexico. This pattern suggests a focus on North America, with a relatively small number of claimed victims during this period. Newman Tractor’s inclusion aligns with the group’s apparent targeting of North American entities within the manufacturing sector.

Technical Analysis

SOCRadar’s Dark Web Monitoring identified Newman Tractor as a victim of the threeam ransomware group. The analysis of a stealer-log sample revealed the presence of ADFS credentials associated with the victim’s internal ERP subdomain. This finding is notable as ADFS credentials grant access to federated systems, potentially including ERP, VPN, email, and other applications integrated into the organization’s identity management infrastructure. Additionally, one external user credential was found on a target-owned URL, and two corporate-attributed credentials were identified on a cloud hosting control panel. The stealer-log records show dates clustered around March 2026, indicating that these credentials may have been exfiltrated and circulating for up to six months prior to the threeam listing. The presence of ADFS credentials signifies a compromise of the organization’s direct authentication infrastructure. An adversary possessing such credentials could potentially authenticate as any federated user across connected systems. The inclusion of credentials for a cloud hosting control panel presents a secondary high-value attack vector, potentially allowing access to server deployments, SSH keys, and backup configurations. Given the identification of these credentials, it is recommended that Newman Tractor rotate all identified credentials immediately. A thorough audit of ADFS authentication logs dating back to March 2026 should be conducted to identify any unauthorized access. Furthermore, the cloud hosting control panel should be assessed for any unauthorized deployments or suspicious activity related to backup access.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.