Ransomware Group ‘DoppelPaymer’ Breached Kimchuk — Electronics Manufacturing Services Firm

The infamous ransomware operator, DoppelPayner — has struck again!

This time they leaked the files of Kimchuk Inc — high tech, high product mix electronics firm specializing in Engineering Design and Electronic Contract Manufacturing Services firm.

The leak was published on their public websites and over 1.5GB of sensitive data has been exposed, including financial records, employees information etc. The group also disclosed the list of the machines, with their DN records as well.

Based on the historic trends of this group, it’s quite probable that the files were leaked due to their ransomware payment demand rejection by the affected organisation.

Screenshot #1
Screenshot #2
Screenshot #3
Screenshot #4
Screenshot #5
Screenshot #6

At the time of writing this advisory, the leak is still available to download.

Cyble leadership has made an attempt to contact the company of the breach and is still waiting to hear a response.

About Cyble:

Cyble Inc.’s mission is to provide organizations with a real-time view of their supply chain cyber threats and risks. Their SaaS-based solution powered by machine learning and human analysis provides organizations’ insights to cyber threats introduced by suppliers and enables them to respond to them faster and more efficiently.

Cyble strives to be a reliable partner/facilitator to its clients allowing them with unprecedented security scoring of suppliers through cyber intelligence sourced from open and closed channels such as OSINT, the dark web and deep web monitoring and passive scanning of internet presence. Furthermore, the intelligence clubbed with machine learning capabilities fused with human analysis also allows clients to gain real-time cyber threat intel and help build better and stronger resilience to cyber breaches and hacks. Due to the nature of the collected data, the company also offer threat intelligence capabilities out-of-box to their subscribers.

THIS POST HAS BEEN EXPORTED FROM OUR MEDIUM CHANNEL

Recent Blogs

Cyble-Blogs-Anonymous-Sudan

Cyble analyzes recent hacktivism claims by Anonymous Sudan impacting US entities including Microsoft Corporation.

Read More »
Cyble-Blogs-LockBit-Ransomware

Cyble analyzes LockBit Ransomware, which is distributed via malicious documents, specifically targeting users in Korea.

Read More »
Cyble-Blogs-HelloTeacher-Malware

Cyble analyzes a new malware “HelloTeacher” masquerading as popular messaging app to target banking users from Vietnam and steals sensitive data.

Read More »
Scroll to Top