SYS::ONLINE
Wasteland.
Briefs1732
Issues22
SinceFeb 2026
LIVE
█ Ransomware KING-INTERNATIONAL 2026-08-06

King International LLC: Gammax Ransomware Claim

"King International LLC, a US wholesaler of fresh fruits and vegetables, has been named as a victim of the Gammax ransomware operation in reporting that traces back to a single threat-intelligence post circulated on…"

King International LLC, a US wholesaler of fresh fruits and vegetables, has been named as a victim of the Gammax ransomware operation in reporting that traces back to a single threat-intelligence post circulated on social media. Undercode News reports the incident disrupted operational systems and data availability at the distributor. As of publication no victim statement, regulatory filing, CERT advisory or law enforcement confirmation has surfaced, and no record count, ransom demand or intrusion timeline has been published by any source available to us. Readers should treat the King International attribution as an operator-side claim amplified by one outlet, not a confirmed breach, while noting that Gammax has been independently observed listing multiple victims across sectors in the same reporting window.

What Happened

The sourcing picture here is thin and worth stating plainly. The only account describing the King International incident is an Undercode News write-up dated August 6, 2026, which itself hedges heavily: it says a "recent report claims" the wholesaler was hit, that the attack is "attributed to" Gammax, and that the disruption to operations and data availability is alleged. The underlying evidence is described as "a cybersecurity post shared on social media." Undercode explicitly states that the available information does not confirm the attack timeline, the initial access method, the volume of stolen data, or whether a ransom demand was issued.

What is better supported is that Gammax is an active operation running a conventional leak-site extortion model. CyberNetSec.io and its syndicated version on DEV Community both document a surge of leak-site postings on July 31, 2026, in which Gammax listed AguAseo, an environmental services provider in Panama, alongside claims from Qilin against Belgian logistics and chemical supply chain firm ADPO, Genesis against Danish SAP Business One specialist Boyum IT Solutions, and further postings from CMD and Unsafe. Those roundups characterise the Gammax listing as signalling a successful breach and data theft, and place all of the groups in the same double-extortion playbook: publish the claim, threaten the data, pressure the payment.

Days later, on August 3, 2026, Undercode reported a second Gammax listing, this time naming real estate brokerage RE/MAX 1st Choice, sourced to a ThreatMon Threat Intelligence Team alert timestamped 21:25:09 UTC+3. That article makes the analytically correct point directly: being listed by a ransomware group is not the same as having a confirmed breach, and such claims should be treated as allegations until the affected organisation, law enforcement, incident responders or independent investigators confirm otherwise. The same caution applies with equal force to King International.

One further note on identity. A separate Dark Eye record tracks a Qilin claim against Lee International, a Korean finance, legal and insurance firm with 101 to 1000 employees, published June 23, 2026. Similar name, different company, different country, different sector, different threat actor. It is not related to the King International claim and should not be conflated with it.

What Was Taken

Nothing is established. No source in this set states a record count, a data volume in gigabytes, a category of stolen information, or a sample of exfiltrated files tied to King International. There is no proof-of-breach gallery, no leak-site screenshot inventory, and no disclosure notification. Where a data-theft claim is asserted at all, it is asserted generically: Undercode describes "data availability" being affected, which is language consistent with encryption rather than exfiltration, and the CyberNetSec roundup describes the broader Gammax pattern as involving data theft for extortion leverage.

That absence is itself the finding. Because the sources give no figures at all, there is no range to report and no competing number to reconcile. Any specific claim about how many records were taken from King International, or what they contained, is currently unsupported.

For context on what a substantiated leak-site listing usually looks like, the Dark Eye record for the unrelated Lee International incident is instructive: it carries a named victim ID, discovery and publication dates, an exposure gap calculation between leak-site appearance and public disclosure, and posted proof artefacts including a file tree, a finance spreadsheet, a passport scan and a signed contract. The King International claim carries none of that in any source available here.

Why It Matters

Food distribution sits in a category of target where downtime converts to pressure faster than in most sectors. Undercode's framing is the standard one and it holds up: logistics, inventory, customer records, supplier communications and operational technology are tightly coupled in modern food supply, so an outage at one distributor propagates to hauliers, retailers, growers and employees. Perishable inventory makes the clock a weapon. Attackers targeting agriculture, food distribution, manufacturing and logistics understand that an operator facing spoiling stock and missed delivery windows has a compressed decision timeline on paying.

The wider pattern in these sources reinforces it. The July 31 leak-site wave hit logistics, environmental services, finance, software and construction across Belgium, Panama, Denmark, Australia and the United States within a single day. Gammax's own confirmed listings in that window include a public utility service provider in Panama, which the roundup flags as a risk to critical and essential services. This is not a group narrowly specialising in food; it is a group taking whatever essential-services victims it can reach.

There is also a measurement problem that defenders should internalise. The Ransomnews Ransomtracker draws an explicit line between two layers: operator claims scraped from leak sites, and a human-verified dataset of 9,389 ransomware attacks since 2018 across 149 countries, confirmed through breach disclosures, regulatory filings, official statements or credible press reporting. Its methodology note states the obvious but frequently ignored consequence: many confirmed attacks never appear on a leak site, and many leak-site claims are never independently confirmed. Legal-ISAC's RansomWatch dashboard aggregates from publicly disclosed incidents on a similar basis. King International currently sits in the unconfirmed claim layer, and treating that layer as ground truth is how threat intelligence inherits an adversary's own inflation.

The Attack Technique

No source identifies the initial access vector, the ransomware payload version, the dwell time, or any indicators of compromise for the King International incident. Undercode offers only a generic description of ransomware tradecraft, noting that such incidents typically involve encrypting systems, stealing data, or combining both through double extortion.

The most concrete technical mapping in this source set is at group level rather than incident level. The CyberNetSec roundup covering the July 31 wave lists the MITRE ATT&CK techniques associated with the activity: Data Encrypted for Impact, Exfiltration to Cloud Storage, Windows Command Shell, and Inhibit System Recovery. That last one matters most operationally. Inhibit System Recovery means shadow copy deletion, backup catalog destruction and recovery-point tampering, and it is the technique that decides whether a food distributor restores inventory systems in hours or negotiates for days. Exfiltration to Cloud Storage points to data leaving over ordinary egress paths to commodity cloud services rather than bespoke channels.

Worth noting alongside this, because supply chain is the framing everyone reaches for: not every supply chain compromise looks like ransomware. Obsidian Security's analysis of the Klue incident, first reported by Reliaquest on June 17, 2026, describes a threat actor tracked as Icarus abusing a compromised Klue to Salesforce integration to exfiltrate millions of CRM records across multiple organisations, with no encryption involved. Attribution there was contested early, with initial speculation pointing at ShinyHunters before multiple sources including Huntress, itself affected, settled on Icarus. Obsidian's point is that over-permissioned, long-lived and poorly monitored OAuth grants let one vendor compromise fan out across many customer tenants. A food distributor's third-party integrations for ordering, telematics, cold-chain telemetry and ERP carry the same structural risk as the SaaS integrations in that case, independent of any ransomware exposure.

What Organizations Should Do

Sources: Ransomware Hits US Food Supplier King International LLC as Gammax A... | Ransomware Roundup: Qilin, Gammax, Genesis, and Othe... - CyberNetS... | Gammax and Karma Ransomware Claims: RE/MAX 1st Choice and SmilePoin... | Lee International — QILIN Ransomware Attack Dark Eye | Ransomtracker Ransomnews | Ransomware Roundup: Multiple Gangs Target Global Industries - DEV C... | Technical Analysis of the Klue Attack: OAuth Abuse, Stale Integrati... | Real-Time Ransomware Tracking Dashboard