Sealcon Data Breach

Alleged

Ransomware claim involving Sealcon.

Published: Sep 22, 2026 Termite
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Sealcon
Industry
Manufacturing
Threat Actor
Termite
Date of Incident
Sep 22, 2026

Executive Summary

Sealcon, a US manufacturer specializing in cable management and electrical fittings, has been listed by the Termite ransomware group. The claim was made on September 22, 2026, and identified through SOCRadar’s Dark Web Monitoring service. The company serves industrial customers across North America and internationally, making it a potential target for cybercriminals seeking to disrupt supply chains or extract financial gains. In the 60 days preceding this listing, Termite claimed six other victims. The group has primarily targeted entities in the United States and China, with a focus on the Manufacturing, Financial Services, and Healthcare sectors. Recent US victims include Everglades Boats, theLender, TruAmerica Multifamily, and Affinia Healthcare. Sealcon’s profile as a mid-sized American industrial manufacturer aligns with Termite’s established targeting patterns, suggesting a consistent strategy in their recent campaigns.

Technical Analysis

SOCRadar’s stealer-log query for the domain sealconusa[.]com returned no records within the queried dataset slice. It is important to note that this query was bounded and paginated, meaning that credentials may still exist under alternative corporate domains, associated with staff personal email aliases, or in underground marketplaces not yet indexed within this specific dataset. The absence of immediate findings does not rule out a compromise. Such limited query results necessitate continued vigilance and further investigation. Appropriate next steps include conducting credential hygiene reviews and maintaining ongoing monitoring to detect any potential unauthorized access or data exfiltration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.