Quick Summary
AllegedExecutive Summary
Eclipse listed Simplex Engineering on its dark web leak site on October 5, 2026, claiming unauthorized access to the company’s systems and threatening to release sensitive corporate data. As an Indian engineering firm, Simplex Engineering is a significant target. Engineering companies possess valuable proprietary technical designs, client project specifications, and manufacturing processes that are prime targets for ransomware groups seeking extortion material. This listing highlights the growing threat to industrial and technological sectors in emerging economies. Eclipse has claimed 11 victims in the past 60 days, with its targets spread across the technology and hospitality sectors in India, Singapore, and the United States. Notable recent victims include ETNA Software, The Japan Times, Rosello et Fils, and Dublin City Schools GA. Simplex Engineering represents Eclipse’s latest victim in India, a region where the group has been actively expanding its presence. This strategic focus on South Asia’s rapidly digitizing industrial sector indicates a deliberate expansion strategy by the ransomware group.
Technical Analysis
SOCRadar’s stealer log query for Simplex Engineering’s domain, part02.simplexengg[.]in, returned no matching records. This absence of data does not definitively confirm that the organization is unaffected, as the query is limited in scope. It is possible that credentials exist under adjacent corporate domains, through personal email aliases used by employees, or within data feeds not covered by the specific query. Additionally, any compromised credentials may have been used and subsequently rotated before the data was indexed. The lack of stealer-log matches suggests that infostealer-driven credential harvesting may not have been the primary method of initial access for this particular incident. Threat actors like Eclipse often employ multiple intrusion vectors, including exploiting vulnerable web-facing applications, conducting spear-phishing campaigns with malicious attachments, or leveraging exploits in third-party software. These alternative methods can provide access to corporate networks without relying on harvested credentials from stealer malware. Engineering firms, particularly those operating in India, are advised to conduct a thorough audit of their network segmentation. It is crucial to differentiate between sensitive project repositories and internet-facing systems. Maintaining offline backups of critical data, such as CAD files and client documentation, is essential for business continuity and recovery. In the event of a confirmed compromise, organizations in India must adhere to CERT-In’s mandatory notification window, which requires reporting within six hours of discovery.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.