Simplex Engineering Data Breach

Alleged

Ransomware claim involving Simplex Engineering

Published: Oct 5, 2026 Eclipse
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Simplex Engineering
Industry
Engineering
Threat Actor
Eclipse
Date of Incident
Oct 5, 2026

Executive Summary

Eclipse listed Simplex Engineering on its dark web leak site on October 5, 2026, claiming unauthorized access to the company’s systems and threatening to release sensitive corporate data. As an Indian engineering firm, Simplex Engineering is a significant target. Engineering companies possess valuable proprietary technical designs, client project specifications, and manufacturing processes that are prime targets for ransomware groups seeking extortion material. This listing highlights the growing threat to industrial and technological sectors in emerging economies. Eclipse has claimed 11 victims in the past 60 days, with its targets spread across the technology and hospitality sectors in India, Singapore, and the United States. Notable recent victims include ETNA Software, The Japan Times, Rosello et Fils, and Dublin City Schools GA. Simplex Engineering represents Eclipse’s latest victim in India, a region where the group has been actively expanding its presence. This strategic focus on South Asia’s rapidly digitizing industrial sector indicates a deliberate expansion strategy by the ransomware group.

Technical Analysis

SOCRadar’s stealer log query for Simplex Engineering’s domain, part02.simplexengg[.]in, returned no matching records. This absence of data does not definitively confirm that the organization is unaffected, as the query is limited in scope. It is possible that credentials exist under adjacent corporate domains, through personal email aliases used by employees, or within data feeds not covered by the specific query. Additionally, any compromised credentials may have been used and subsequently rotated before the data was indexed. The lack of stealer-log matches suggests that infostealer-driven credential harvesting may not have been the primary method of initial access for this particular incident. Threat actors like Eclipse often employ multiple intrusion vectors, including exploiting vulnerable web-facing applications, conducting spear-phishing campaigns with malicious attachments, or leveraging exploits in third-party software. These alternative methods can provide access to corporate networks without relying on harvested credentials from stealer malware. Engineering firms, particularly those operating in India, are advised to conduct a thorough audit of their network segmentation. It is crucial to differentiate between sensitive project repositories and internet-facing systems. Maintaining offline backups of critical data, such as CAD files and client documentation, is essential for business continuity and recovery. In the event of a confirmed compromise, organizations in India must adhere to CERT-In’s mandatory notification window, which requires reporting within six hours of discovery.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.