# Qilin ransomware claims Textile City victim

Published: 2026-09-22 · Severity: high · Sectors: manufacturing
Canonical: https://vorant.io/reports/9c0afc57-4ea0-5328-bf42-2df43ab6c18b/qilin-ransomware-claims-textile-city-victim

> Qilin ransomware gang listed 'Textile City' as a victim on its leak site, with limited compromise details disclosed.

This entry is a ransomware victim listing sourced from ransomware.live, tracking a claim by the Qilin ransomware group against an organization referred to as 'Textile City'. The listing indicates a small number of compromised employee credentials (1 employee, 8 third-party employee credentials) and 4 external attack surface findings, likely derived from infostealer log correlation (the article references Hudson Rock's infostealer-to-ransomware intelligence tooling as a sponsor). No further technical details, TTPs, ransom demands, or data samples are provided in this record.

Defenders in the textile/manufacturing or related supply-chain sectors should treat this as a low-detail indicator that Qilin activity is ongoing and that credential exposure via infostealers remains a common precursor to ransomware intrusions. Organizations should monitor for employee and third-party credential leaks, review external attack surface exposure, and ensure infostealer malware detection and credential hygiene practices are in place, particularly around VPN, RDP, and other remote access services often abused by Qilin affiliates.

## Mentioned in this report

- Threat actors: qilin
- Malware: Qilin

Source reporting: https://www.ransomware.live/id/VGV4dGlsZSBDaXR5QHFpbGlu

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9c0afc57-4ea0-5328-bf42-2df43ab6c18b/qilin-ransomware-claims-textile-city-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
