VORANT. Threat Intelligence Sign in Get the full feed

Clop Ransomware Claims Industrial Rubber Company

high threat manufacturing

The Clop ransomware group listed U.S. industrial rubber manufacturer IRCO.COM as a victim, claiming theft of employee and third-party credentials.

Ransomware.live's tracking data shows IRCO.COM, the web presence of Industrial Rubber Company, a U.S. manufacturer and distributor of industrial rubber products serving manufacturing, oil and gas, and construction clients, has been added to a ransomware group's victim list (identified in the record as Clop). The listing reports 125 compromised employees, 45 compromised user accounts, 108 third-party employee credential exposures, and an external attack surface of 83 assets, indicating the group is claiming a broad credential and data compromise rather than disclosing specific stolen files.

The bulk of the technical detail in the source page consists of the victim's public DNS records (MX, TXT/SPF, and domain-verification tokens for services such as Microsoft 365, Salesforce, Atlassian, Zscaler, Cisco, and others), which reflect the organization's legitimate SaaS footprint rather than attacker infrastructure. No malicious IOCs, exploited CVEs, or confirmed initial-access vector were disclosed in this listing. As a routine leak-site victim posting without additional technical evidence of the intrusion method, this should be treated as a standard ransomware extortion claim pending further corroboration.

Mentioned in this report

Threat actors Clop
Malware Clop

Source reporting: https://www.ransomware.live/id/SVJDTy5DT01AY2xvcA==

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free