States Industries Data Breach

Alleged

Ransomware claim involving States Industries

Published: Oct 3, 2026 Storm
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
States Industries
Industry
Business Services
Threat Actor
Storm
Date of Incident
Oct 3, 2026

Executive Summary

Storm ransomware has targeted States Industries, a U.S.-based industrial manufacturer, listing the company on its dark web leak site on October 3, 2026, and claiming the exfiltration of corporate data. The nature of the identified credential profile is particularly notable, with seven stealer-log records suggesting a clear workstation compromise pattern. This pattern included credentials for Reply.io, a sales automation platform, and Lusha, a business intelligence tool used for contact and sales data. The exposure of these credentials is significant as these platforms often contain sensitive customer and prospect information, making them valuable for ransomware actors. The sustained capture of credentials from a single identity over an eight-month period points to a persistent endpoint infection. Storm ransomware has demonstrated a consistent focus on U.S. manufacturing and professional services sectors over the past 60 days. Their operational modus operandi involves leveraging credentials obtained from infostealer malware for initial access, followed by lateral movement through cloud Software as a Service (SaaS) accounts before deploying encryption. Manufacturing companies that heavily rely on cloud-based sales and business management tools have become a recurring target for this group. This pattern suggests that Storm actively seeks out organizations with a significant digital footprint in these interconnected cloud services, exploiting the reliance on such tools for operational efficiency.

Technical Analysis

SOCRadar’s investigation identified seven stealer-log records associated with States Industries, concerning one employee whose email was partially masked as tne****h@statesind[.]com. These records spanned from October 2025 through June 2026, indicating an eight-month period of credential exposure. The compromised credentials included access to Reply.io, a platform for email outreach and sales automation, and Lusha, a B2B contact and sales intelligence service. Both of these services store commercially sensitive data, such as contact lists, prospect databases, and client communication history, which can be leveraged by threat actors for extortion or used to facilitate further attacks. The capture of credentials for multiple distinct platforms from a single identified user strongly suggests a persistent infection on a workstation. This type of infection, driven by infostealer malware, is a common vector for ransomware groups like Storm. The exposure of credentials for sales and business intelligence tools is particularly concerning, as it grants attackers access to valuable business data and potentially facilitates further network infiltration by providing legitimate access points. States Industries should immediately initiate endpoint forensics on the affected workstation. It is crucial to rotate all credentials associated with that endpoint, specifically including those for Reply.io and Lusha. Furthermore, a thorough audit of both platforms is recommended to identify any unauthorized data exports that may have occurred between October 2025 and June 2026. If the captured contact databases contain personal data, States Industries must assess applicable U.S. state privacy law breach notification requirements.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.