Quick Summary
AllegedExecutive Summary
Sun Dolphin Boats, a manufacturing company based in the United States, was listed as a victim by the qilin ransomware group on July 9, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring. The company operates in the consumer goods manufacturing sector, with both a public-facing e-commerce presence and production operations. The qilin group has shown a consistent interest in targeting US manufacturers. Over the 60 days preceding this listing, qilin claimed 146 other victims, making it a highly active ransomware operation. The group predominantly targets the business services, manufacturing, and healthcare sectors, with a significant focus on victims in the United States, Australia, and the United Kingdom. Sun Dolphin Boats aligns with qilin’s recent focus on US manufacturers.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a low-confidence exposure for the sundolphin.com domain in the 60 days prior to the listing. This exposure consisted of a small number of credentials, primarily linked to the public website, including two consumer email accounts and two unclassified handles. No corporate email accounts, identity provider logins, or internal endpoints were identified in this sample. The evidence suggests a potential for customer account takeover or supplier risk rather than a direct corporate intrusion. The credentials were from October 2025 to June 2026. While infostealer-harvested credentials are a known initial access vector for ransomware groups like qilin, the specific credentials found in this instance do not confirm their use by the qilin group. The exposed consumer-tier records do not fit the typical pattern of corporate credential theft used for initial access. The leak site listing and the public website exposure should be considered as parallel observations, and a direct causal link to qilin’s activity cannot be definitively inferred from the stealer log data. Recommended actions include monitoring for account takeover on the public site and implementing standard corporate credential hygiene practices.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.