Quick Summary
AllegedExecutive Summary
Rohloff Group, an engineering and industrial manufacturer based in South Africa, was listed on the INC Ransom dark web portal on August 27, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. While South African targets are less common for INC Ransom, the group primarily focuses on North America and Europe. The company’s industry, manufacturing, is a frequent target for ransomware groups. Over the past 60 days, INC Ransom has claimed 49 other victims, predominantly in professional services, manufacturing, and healthcare sectors. The group’s primary geographic targets are the United States, Canada, and Switzerland. Recent manufacturing victims attributed to INC Ransom include Universal Plastics Inc., BANGKOKCABLE, TRULITE GLASS & ALUMINUM SOLUTIONS, and DUCON, suggesting a pattern that aligns with Rohloff Group’s operational profile.
Technical Analysis
SOCRadar’s telemetry data yielded 26 records associated with the domain rohloffgroup[.]co[.]za. Among these records, five were confirmed corporate credentials linked to the email domain @rohloffgroup[.]co[.]za. Specifically, two credentials provided direct access to Microsoft 365 via login[.]microsoftonline[.]com, and three were found on the organization’s internal employee self-service system. An additional 16 records indicated external users accessing this same internal portal, suggesting a broad exposure to HR and authentication infrastructure. The data retrieved has a freshness window spanning from June 2024 to August 2026, covering over two years. Credentials for the M365 tenant, especially when found in stealer logs, are considered highly valuable commodities on underground marketplaces for initial access. The discovery of two such credentials, combined with access to an internal HR system that has not been rotated in over two years, presents a significant exposure profile that is actively sought by ransomware operators and their initial access brokers. This type of exposure can facilitate ransomware deployment. Continued dark web monitoring for mentions of Rohloff Group and related domains is recommended. Proactive credential hygiene checks, including thorough password rotation and multi-factor authentication reviews for all accounts, are crucial. Additionally, organizations should monitor access logs for Microsoft 365, VPNs, and remote access portals for any anomalous activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.