Quick Summary
AllegedExecutive Summary
On 2026-08-30, the ransomware group iah6477 claimed Swagelok, a manufacturing firm based in the United States, as a victim. SOCRadar CTI identified 18 credential records associated with swagelok[.]com, with timestamps ranging from December 4, 2024, to August 29, 2026, just one day prior to the listing. This includes one Microsoft 365 employee credential, ten external records on organizational portals, and one corporate third-party credential, along with six records of an unclear classification. The extensive timeframe of compromised credentials suggests a prolonged period of potential vulnerability for the company. The iah6477 group has claimed seven victims in the past 60 days, primarily targeting organizations in the United States within the Manufacturing and Professional Services sectors. Swagelok’s profile as a US-based manufacturing entity aligns perfectly with iah6477’s typical targeting patterns. The group’s operational methodology appears to involve deliberate and targeted access acquisition rather than opportunistic broad-spectrum attacks, making the Swagelok listing consistent with their established modus operandi.
Technical Analysis
SOCRadar CTI’s analysis of swagelok[.]com revealed a “severe_exposure_in_sample” status, indicating a significant number of credential records found within the queried datasets. The breakdown of these records includes one Microsoft 365 employee credential, which directly grants access to the organization’s identity infrastructure. Additionally, ten external records were found on organizational portals, suggesting potential exposure of browser-stored credentials across various domains due to infostealer infections on employee devices. A further one corporate third-party credential and six unclassified records were also identified. The timestamps associated with these records span from December 4, 2024, to August 29, 2026. This broad temporal distribution, covering approximately 20 months, strongly suggests multiple instances of stealer infections targeting Swagelok personnel over an extended period. The variety of portal types and the mixed classification of the credentials indicate a complex landscape of potential exposures that requires thorough investigation. The presence of an exposed Microsoft 365 credential is of particular concern, as it can serve as a direct gateway to critical identity management systems. The external portal credentials, likely captured by infostealers, highlight the risk of compromised user accounts across various external services. The six unclassified records necessitate manual review to determine if they represent further access points to sensitive systems or data. Given the 20-month exposure window, a comprehensive forensic review of historical authentication logs is crucial to identify any unauthorized access that may have occurred prior to the current date. This should go beyond simple credential rotation to ensure all potential compromise vectors are addressed.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.