BaseLeak
802 subscribers
44 photos
170 links
Download Telegram
πŸ” INCIDENT: SPKAA.COM

πŸ“… Attacker's Claim Date: August 2026 (Cl0p group)

🦠 Attacker: Cl0p ransomware group

🎯 Compromised Domain: SPKAA.COM

🏒 About the Company: SPKAA.com is a domain listed among nearly 50 companies targeted by the Cl0p ransomware group in a mass extortion campaign conducted in August 2026 . The campaign also included major global corporations such as Shell, Philips, General Electric, and Fiserv .

πŸ’° Ransom Demand: $5,000,000

πŸ“¦ Total claimed archive size: 581 GB

πŸ“‚ WHAT WAS CLAIMED TO BE LEAKED:

β€’ Database files
β€’ Project files

🧾 STATUS:
⚠️ To avoid publication contact us before your name is revealed and your data" . No official confirmation or statement from the company regarding the breach has been found at this time. The claim has not been independently verified.

πŸ’« Note: The attack is part of a broader Cl0p campaign believed to have exploited vulnerabilities in PTC Windchill and FlexPLM software used in engineering and manufacturing processes . The $5,000,000 ransom demand appears to be a standard figure used by Cl0p across multiple victims in this campaign.
-----
πŸ” INCIDENT: IVALUESYS.COM

πŸ“… Attacker's Claim Date: August 12, 2026

🦠 Attacker: Cl0p ransomware group

🎯 Compromised Domain: IVALUESYS.COM

🏒 About the Company: Ivaluesys (Shanghai Weiling Information Technology Co., Ltd.) is a Chinese technology company founded in 2011, specializing in R&D solutions for the manufacturing sector. The company provides PLM (Product Lifecycle Management)/ALM (Application Lifecycle Management) IT services and CAD/CAE/CAM software solutions for industries including consumer electronics, photovoltaics, automotive electronics, medical devices, semiconductors, and industrial automation. Headquartered in Shanghai, the company also has offices in Shenzhen, Fuzhou, and Nanchang.

πŸ’° Ransom Demand: $5,000,000

πŸ“¦ Total claimed archive size: 109 GB

πŸ“‚ WHAT WAS CLAIMED TO BE LEAKED:

β€’ Database files
β€’ Project files
β€’ Backups

🧾 STATUS:
⚠️ Ivaluesys was listed among nearly 50 companies worldwide targeted in Cl0p's mass extortion campaign, which also included Shell, Philips, and General Electric. The attacks have been linked to vulnerabilities in PTC Windchill and FlexPLM software used in engineering and manufacturing processes. Ivaluesys, as a PLM service provider and PTC partner, may be particularly relevant to this attack vector. No official confirmation or statement from Ivaluesys regarding the breach has been found at this time. The claim has not been independently verified.

πŸ’« Note: Ivaluesys is a Chinese company serving as a PLM solutions provider for manufacturing clients, making it a potentially attractive target for data extortion.
----
πŸ” INCIDENT: NUOVACMM.COM

πŸ“… Attackerβ€˜s Claim Date: August 2026

🦠 Attacker: Cl0p ransomware group

🎯 Compromised Domain: NUOVACMM.COM

🏒 About the Company: Nuova C.M.M. S.r.l. is an Italian technology company specializing in the design, construction, and supply of welding automation systems . Founded in 1974, the company serves naval, offshore, and industrial sectors . Headquartered in Tezze sul Brenta, Italy,

πŸ’° Ransom Demand: $5,000,000

πŸ“¦ Total claimed archive size: 279 GB

πŸ“‚ WHAT WAS CLAIMED TO BE LEAKED:

β€’ Database files
β€’ Project files
β€’ Software installers

🧾 STATUS:
⚠️ This attack is part of a broader Cl0p campaign targeting nearly 50 companies worldwide, including Shell, Philips, and General Electric . The attacks have been linked to vulnerabilities in PTC Windchill and FlexPLM software used in engineering and manufacturing processes . According to Hudson Rock, similar domains in the Nuova CMM ecosystem (nuovamacut.it) have previously been compromised with exposed employee credentials β€” at least 147 compromised logins, with URLs like http://crm.nuovamacut.it/login.aspx, http://portal.nuovamacut.it/Login, and https://portal.nuovamacut.it/changepassword being targeted .

No official confirmation or statement from Nuova C.M.M. regarding the breach has been found at this time. The claim has not been independently verified.

πŸ’«
====
πŸ” INCIDENT: THERMOS.COM

πŸ“… Date of attackers' claim: August 2026

🦠 Attacker: Ransomware group Cl0p

🎯 Compromised domain: THERMOS.COM

🏒 About the company: Thermos L.L.C. is an American manufacturer of insulated food and beverage containers and drinkware. The company was founded in 1904, and its headquarters is located in Schaumburg, Illinois, USA. Thermos is one of the most recognizable brands in its category. The company's estimated annual revenue ranges from $77 million to $250 million.

πŸ’° Ransom demanded: $5,000,000

πŸ“¦ Total volume of the claimed archive: 285 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files
β€’ Software installers

🧾 STATUS:
⚠️ Claim by the hacker group Cl0p. The attack is part of a large-scale campaign in which about 50 companies worldwide were targeted, including Shell, Philips, General Electric, and others. The attacks are presumably linked to vulnerabilities in PTC Windchill and FlexPLM software used in engineering and manufacturing processes. At this time, there is no independent confirmation of the leak and no official statement from Thermos.

πŸ’« Note: Thermos is a publicly known brand with a long history, which makes it an attractive target for extortionists.

----
πŸ” INCIDENT: BRILLONCONSUMER.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: BRILLONCONSUMER.COM

🏒 About the company: Brillon Consumer Products Pvt Ltd is an Indian consumer goods company, a joint venture between SC Johnson and Bansk Group. Its headquarters is located in Gurugram, Haryana, India. The company owns brands such as All Out, Baygon, Mr Muscle, Glade, Kiwi, and Dranex. Its estimated annual revenue ranges from β‚Ή500 to β‚Ή1,000 crore (~$60–120 million).

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 22.4 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

🧾 STATUS:
⚠️ Claim by the hacker group Clop. The group warned that the full data leak would be published unless the company makes contact. At this time, there is no independent confirmation of the leak and no official statement from Brillon Consumer. It should be noted that some sources flag Clop's claims as unverified.

πŸ’« Note: Brillon Consumer is a notable player in the Indian FMCG market with a portfolio of well-known brands, which makes it an attractive target for extortionists.

β€”β€”-
πŸ” INCIDENT: SUUNTO.CN (SUUNTO.COM)

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: SUUNTO.CN (SUUNTO.COM)

🏒 About the company: Suunto Oy is a Finnish manufacturer of sports watches, dive computers, and precision instruments. The company was founded in 1936, and its headquarters is located in Vantaa, Finland. In 2022, Suunto was acquired from Amer Sports by Chinese company Liesheng Technology . The brand's products are sold in more than 100 countries worldwide . The estimated annual revenue is approximately $108–111 million .

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 1470 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 1
β€’ Compromised users: 3139
β€’ Third-party employee credentials: 4
β€’ External attack surface: 101

🧾 STATUS:
⚠️ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM . The attackers deployed a custom JSP web shell capable of decrypting credentials, exfiltrating files, and enabling remote code execution . According to Clop's statement, "The full leak will be published soon, unless a company representative contacts us" . At this time, there is no independent confirmation of the leak and no official statement from Suunto.

πŸ’« Note: Suunto is a Finnish brand with a 90-year history and global recognition. The detected infostealer traces (3139 compromised users, 4 third-party employee credentials) indicate that access to the environment may have been obtained not only through the Windchill vulnerability but also through previously compromised credentials, which significantly expands the attack surface.

---
πŸ” INCIDENT: SMAPCENTER.UAH.EDU

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: SMAPCENTER.UAH.EDU

🏒 About the organization: SMAP Center (Systems Management and Production Center) is a research center at the University of Alabama in Huntsville (UAH). The center participates in U.S. Department of Defense research, particularly on diminishing manufacturing sources and material shortages (DMSMS) in weapon systems, and also runs STEM education and medical simulation projects (MEDNET). UAH's annual research expenditure is about $154.5 million, with 17 research centers at the university. The center's estimated revenue is $113 million.

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 6.08 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

πŸ”“ ADDITIONAL COMPROMISE DATA:

β€’ Compromised employees: not disclosed
β€’ Compromised users: not disclosed
β€’ Third-party employee credentials: not disclosed
β€’ External attack surface: not disclosed

Note: No HudsonRock data was found for SMAPCENTER.UAH.EDU. The attack vector was a server-side application vulnerability (PTC Windchill RCE), not endpoint infostealer malware, so no infostealer credential data is expected for this target. To verify manually, the domain can be checked via HudsonRock's free lookup tool.

🌐 INFRASTRUCTURE:

β€’ IP address: 146.229.99.30, Huntsville, Alabama, USA
β€’ ASN: AS10364, University of Alabama in Huntsville (UAH)
β€’ Subdomain: apps.smapcenter.uah.edu (time-tracking system, protected by DUO MFA)
β€’ Owning entity: Systems Management and Production Center, UAH research center, network range 146.229.0.0/16

🧾 STATUS:
⚠️ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM. The vulnerability is an insecure deserialization flaw enabling remote code execution via the wt.fv.uploadtocache.DoUploadToCache_Server upload path. In Windchill environments, Clop deployed a custom JSP web shell capable of decrypting credentials, enumerating file vaults, and exfiltrating engineering data, receiving commands via a custom X-windchill-req HTTP header. The same campaign wave included Shell, Philips, General Electric, and roughly 50 other organizations. According to Clop's statement, "The full leak will be published soon, unless a university representative contacts us." At this time, there is no independent confirmation of the leak and no official statement from UAH or the SMAP Center.

πŸ’« Note: The SMAP Center is tied to defense research and management systems for the U.S. Department of Defense, which makes it a particularly sensitive target for extortionists.

---
πŸ” INCIDENT: TRISTAR.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: TRISTAR.COM

🏒 About the company: Tristar Corporation is an American corporation headquartered in the USA. The company's exact business profile is not disclosed in open sources, but its claimed annual revenue is estimated at $1 billion.

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 1579.9 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 0
β€’ Compromised users: 1
β€’ Third-party employee credentials: 8
β€’ External attack surface: 1

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: tristar-com.mail.protection.outlook.com (Microsoft 365)
β€’ SaaS services: Mailchimp, Mailgun, Microsoft 365

🧾 STATUS:
⚠️ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026, during which the group claimed dozens of victims in a short period. The total volume of data across all victims in this wave is estimated at roughly 23 TB and appears to include CAD files, databases, backups, engineering drawings, and other documents. Tristar Corporation is listed among the victims of this campaign. At this time, there is no independent confirmation of the leak and no official statement from the company.

πŸ’« Note: The claimed $1 billion revenue combined with the relatively small footprint of detected compromise (1 user, 1 asset) may indicate that the primary value of the data for extortionists lies in the archive contents rather than in employee credentials.

___
πŸ” INCIDENT: MAMASANDPAPAS.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: MAMASANDPAPAS.COM

🏒 About the company: Mamas & Papas is a British retailer of baby and nursery products, specialising in pushchairs, nursery furniture, car seats, clothing, and accessories. The company was founded in 1981, with its headquarters in Huddersfield, England. The brand operates more than 60 stores across the UK and sells its products in over 30 countries worldwide. In the 2026 financial year, the company's revenue reached £170 million, up 4% year over year .

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 1.18 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

🧾 STATUS:
⚠️ Claim by the hacker group Clop. The attack is part of a Clop campaign in August 2026, during which the group claimed dozens of victims. According to Clop's statement: "The data will be published if the company does not engage in negotiations within the specified timeframe" . However, on August 14, 2026, the Mamas & Papas PR team contacted security researchers and stated: "We have found no evidence of the affected software nor any indicators of unauthorised access to, or compromise of, customer or company data" . At the time of publication, there is no independent confirmation of the leak.

πŸ’« Note: Mamas & Papas is the UK market leader in baby products with a share of around 25%. The absence of any data samples, screenshots, or other evidence on the Clop page is atypical for the group, which raises further doubts about the claim's credibility .

---
πŸ” INCIDENT: CORNELIUS.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: CORNELIUS.COM

🏒 About the company: Cornelius Inc. is an American manufacturer of beverage dispensing equipment, founded in 1931. The company specialises in fountain, frozen, and juice dispensers, as well as commercial ice machines. Cornelius is part of Marmon Foodservice Technologies, which in turn is owned by Marmon Holdings and Berkshire Hathaway. Its headquarters is located in Osseo, Minnesota, USA. Products are supplied to more than 100 countries, and its workforce numbers between 1,000 and 5,000 employees . The claimed annual revenue is $269.8 million .

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 3684 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files
β€’ PDF documents
β€’ TXT files
β€’ DOC documents

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 0
β€’ Compromised users: 12
β€’ Third-party employee credentials: 16
β€’ External attack surface: 3

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: cornelius-com.mail.protection.outlook.com (Microsoft 365)
β€’ SaaS services: Microsoft 365, Smartsheet

🧾 STATUS:
⚠️ Claim by the hacker group Clop. On August 12, 2026, Clop listed Cornelius Inc. on its leak site, claiming the theft of 3684 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. However, on August 13, 2026, it emerged that law firm Bryson, Harris, Suciu, DeMay PLLC had launched an investigation into the potential data breach, inviting current and former employees as well as commercial distributors to participate in a preliminary investigation for a potential class action lawsuit . At the time of publication, Cornelius Inc. had made no official statement confirming or denying the leak.

πŸ’« Note: The absence of compromised employees (0) alongside 12 compromised users and 16 third-party employee credentials may indicate that access to the environment was obtained primarily through external accounts or contractors rather than through direct company employee credentials.

---
πŸ” INCIDENT: MAMMUT.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: MAMMUT.COM

🏒 About the company: Mammut Sports Group AG is a Swiss manufacturer of high-quality outdoor equipment and apparel for mountaineering and climbing. The company was founded in 1862, with its headquarters in Seon, Switzerland. Mammut operates in around 40 countries and employs approximately 800 people . In 2026, the company was acquired by Chinese private equity firm CPE源峰 from Jacobs Capital . Revenue for 2025 was approximately 400 million Swiss francs (roughly $281 million at current exchange rates) .

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 136 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ .png files
β€’ Windchill files

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 1
β€’ Compromised users: 173
β€’ Third-party employee credentials: 1
β€’ External attack surface: 42

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: mx1.mammut.ch, mx2.mammut.ch
β€’ SaaS services: Apple, Atlassian, Microsoft 365, SendGrid

🧾 STATUS:
⚠️ Claim by the hacker group Clop. On August 12, 2026, Clop listed MAMMUT.COM on its leak site, claiming the theft of 136 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. Important: RedPacket Security notes that listings attributed to Clop "have been reported as including unverified or fabricated victim claims" . At the time of publication, there is no independent confirmation of the leak and no official statement from Mammut.

πŸ’« Note: This is not the first attack on Mammut. In May 2025, the company was already targeted by ransomware group DATACARRY, which, according to trackers, also operated through credential compromise (infostealer) . A repeat appearance on victim lists within a year may indicate either persistent credential security issues or reuse of previously stolen data.

β€”β€”
πŸ” INCIDENT: PARTECH.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: PARTECH.COM

🏒 About the company: According to Clop's claim, PARTECH.COM belongs to a company with annual revenue of $475,700,000. However, precise identification is complicated: the domain partech.com is associated with two distinct organizations β€” French venture capital firm Partech (offices in Paris, San Francisco, Berlin, Dakar; €1.5B under management) and American PAR Technology Corporation (NYSE: PAR), whose fiscal year 2026 revenue guidance is $516–523 million . The claimed revenue of $475.7 million is closer to PAR Technology's figures than to Partech's estimates ($39.2M) . Clop does not specify which entity is the actual victim.

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 24 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files
β€’ CAD files
β€’ Backups

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 2
β€’ Compromised users: 8
β€’ Third-party employee credentials: 16
β€’ External attack surface: 16

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: partech-com.mail.protection.outlook.com (Microsoft 365)
β€’ SaaS services (per TXT records): Atlassian, Wrike, Amazon, Shopify, Google, Cloudflare, Smartsheet, BrowserStack, Zoom, Anthropic, Miro, ConfigCat, Intacct, and others

🧾 STATUS:
⚠️ Claim by the hacker group Clop. On August 12, 2026, Clop listed PARTECH.COM on its leak site, claiming the theft of 24 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.

πŸ’« Note: The most significant feature of this incident is the ambiguity in victim identification. The domain partech.com is used by at least two organizations with different profiles, which complicates assessing the credibility of the claim and the potential impact. If the victim is PAR Technology (a restaurant technology provider), the leak of CAD files and backups could affect intellectual property and client data; if Partech (a venture capital firm), it could involve confidential information of portfolio companies and investors.

β€”β€”
πŸ” INCIDENT: STARKEY.COM

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: STARKEY.COM

🏒 About the company: Starkey Hearing Technologies, Inc. is an American hearing aid manufacturer founded in 1967. Its headquarters is located in Hopkins, Minnesota, USA. The company is the largest American-owned hearing aid manufacturer and ranks among the global top five with a market share of around 15% . Starkey specialises in AI-integrated hearing aids with features such as step tracking, fall detection, and language translation . Its annual revenue is approximately $1 billion .

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 3030 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Databases
β€’ Project files

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 10
β€’ Compromised users: 11
β€’ Third-party employee credentials: 18
β€’ External attack surface: 38

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: starkey-com.mail.protection.outlook.com (Microsoft 365)
β€’ SaaS services (per TXT records): Dynatrace, Google, Apple, Cisco, Anthropic, Firebase, Zapier, Microsoft, OpenAI, KnowBe4

🧾 STATUS:
⚠️ Claim by the hacker group Clop. On August 12, 2026, Clop listed STARKEY.COM on its leak site, claiming the theft of 3030 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. At the time of publication, there is no independent confirmation of the leak and no official statement from Starkey.

πŸ’« Note: Starkey is the only American-owned hearing aid manufacturer and an active player in AI-driven medical technology. The 3030 GB leak volume is one of the largest in the current Clop attack wave, which may indicate a significant volume of intellectual property, including project data and research databases.

____
πŸ” INCIDENT: LARGAN.COM.TW

πŸ“… Date of attackers' claim: August 12, 2026

🦠 Attacker: Ransomware group Clop

🎯 Compromised domain: LARGAN.COM.TW

🏒 About the company: Largan Precision Co., Ltd. is a Taiwanese optical lens manufacturer and a key supplier of camera modules for Apple. The company was founded in 1987, with its headquarters in Taichung, Taiwan. Largan is the world's largest manufacturer of smartphone lenses and holds a significant share of the high-end optics market. Its claimed annual revenue is $1.7 billion.

πŸ’° Ransom demanded: not specified

πŸ“¦ Total volume of the claimed archive: 56 GB

πŸ“‚ WHAT IS CLAIMED ABOUT THE LEAK:

β€’ Project files
β€’ Software (Soft)

πŸ”“ ADDITIONAL COMPROMISE DATA (HudsonRock):

β€’ Compromised employees: 0
β€’ Compromised users: 43
β€’ Third-party employee credentials: 0
β€’ External attack surface: 6

🌐 DETECTED INFRASTRUCTURE:

β€’ MX records: mail.largan.com.tw, mailgw1.largan.com.tw, mailgw2.largan.com.tw
β€’ SPF record: v=spf1 ip4:219.87.176.11 ip4:219.87.176.7 ip4:60.248.234.226 ip4:123.51.154.9 -all

🧾 STATUS:
⚠️ Claim by the hacker group Clop. On August 12, 2026, Clop listed LARGAN.COM.TW on its leak site as part of a large-scale campaign linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.8) in PTC Windchill and FlexPLM . The vulnerability involves insecure deserialization and improper input validation, allowing an unauthenticated remote attacker to execute arbitrary code . Clop used a custom JSP web shell to access Windchill data, including credential decryption and file exfiltration . Largan Precision is listed among more than 40 alleged victims in the campaign alongside Shell, Philips, Fiserv, Zebra Technologies, Mindray, and others . According to Clop's statement: "The full database will be leaked if Largan Precision Co., Ltd. does not contact us to negotiate" . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.

πŸ’« Note: Largan Precision is a critical Apple supplier in the camera module supply chain, which makes a potential leak of project data and software particularly sensitive. However, the absence of compromised employees (0) alongside 43 compromised users may indicate access through external accounts or contractors rather than direct employee credentials.