Orex Trading Co., Ltd. Data Breach

Alleged

Ransomware claim involving Orex Trading Co., Ltd.

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Orex Trading Co., Ltd.
Industry
Business Services
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

Krybit ransomware has claimed Orex Trading Co., Ltd. as a victim, listing the company on its dark web portal on September 1, 2026. This listing was flagged by SOCRadar’s Dark Web Monitoring. Orex Trading, a commercial trading entity based in Thailand, serves clients across the region. Its operations in the trading sector, coupled with its regional presence, may have made it an attractive target for ransomware and extortion activities. Krybit has been highly active, claiming 58 other victims within the preceding 60 days. The group’s targeting patterns primarily include Professional Services, Other, and Technology industries. Geographically, Krybit shows a concentration in India, Thailand, and Brazil, with Thailand being a consistent focus. This pattern aligns with the listing of Orex Trading, as the ransomware group frequently targets entities in this region. Other notable victims from Thailand listed by Krybit include sunsea.co[.]th, Le Conseil Gabonais des Chargeurs, LHYK Marine Pte Ltd, and CH. Karnchang Public Company Limited.

Technical Analysis

A query of stealer-log data for orex[.]co.th revealed significant findings, with 26 records spanning from December 2024 through August 2026. These records indicate a substantial dwell window of eight months where mail server credentials were persistently exposed without rotation. The compromised mail infrastructure offers attackers potential visibility into internal communications, password reset mechanisms, and partner email exchanges, which can be exploited for ransomware staging and to enhance double-extortion leverage. The prolonged exposure of mail server credentials, specifically on domains like mail.orex[.]co.th (6 records) and smtpmail.orex[.]co.th (5 records), presents a critical risk. Additionally, Apple ID accounts linked to corporate email addresses and seven other records related to CRM, logistics booking systems, and regional news services were also identified. This breakdown includes 16 employee credentials, highlighting a significant risk of corporate intrusion. The eight-month window of unrotated mail server credentials is a serious concern. It is imperative for Orex Trading Co., Ltd. to rotate these credentials immediately and conduct a thorough review of inbox access logs dating back to December 2024. While the CRM and logistics booking records are secondary, they should also be audited for any signs of data exfiltration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.