# Chaos ransomware claims Advantech as victim

Published: 2026-09-29 · Severity: high · Sectors: manufacturing, technology
Canonical: https://vorant.io/reports/cf15a47c-941a-5524-bd46-6f8caecde1a0/chaos-ransomware-claims-advantech-as-victim

> Ransomware.live's leak-site tracker lists industrial hardware maker Advantech.com as a victim of the Chaos ransomware group.

The listing on ransomware.live records Advantech.com as a claimed victim of the Chaos ransomware operation, based on data posted to the group's leak site. The entry itself contains no confirmed technical details of the intrusion — no malware samples, exploited CVE, or infrastructure IOCs are disclosed — but does cite aggregate exposure figures: 22 compromised employee accounts, 1,581 compromised user records, 63 third-party employee credential sets, and 143 external attack-surface findings, alongside DNS records for the domain. The post is sponsored by Hudson Rock, promoting its infostealer-intelligence tooling, suggesting the exposure may be linked to credential-stealing malware infections rather than a directly disclosed ransomware payload or exploitation chain.

Defenders at Advantech or its supply chain should treat this as a signal to audit for credential exposure and infostealer infections among employees and third parties, rotate any potentially compromised credentials, and monitor for anomalous authentication attempts using leaked employee or third-party credentials. Given the sparse technical detail, this should be treated as an unconfirmed leak-site claim pending further validation, with follow-up monitoring of Advantech's official disclosures and threat intelligence feeds for corroboration.

## Mentioned in this report

- Threat actors: chaos
- Malware: Chaos

Source reporting: https://www.ransomware.live/id/YWR2YW50ZWNoLmNvbUBjaGFvcw==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cf15a47c-941a-5524-bd46-6f8caecde1a0/chaos-ransomware-claims-advantech-as-victim.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
