SYS::ONLINE
Wasteland.
Briefs2208
Issues24
SinceFeb 2026
LIVE
█ Ransomware NAMYANG-INDUSTRIAL 2026-08-24

Namyang Industrial: Barracuda Ransomware Data Leak

"The ransomware crew operating as Barracuda has moved a South Korean manufacturer from its "for sale" tier to a free public dump. Namyang Industrial Co., Ltd., trading as Namyang Nexmo, is now the subject of a leak-site…"

The ransomware crew operating as Barracuda has moved a South Korean manufacturer from its "for sale" tier to a free public dump. Namyang Industrial Co., Ltd., trading as Namyang Nexmo, is now the subject of a leak-site posting advertising 17,641,181 CSV rows totalling 2.51 GB, described by the actor as an "infrastructure dump, not website." Every source available for this brief is a third-party tracker, aggregator, or breach-monitoring vendor. There is no statement from Namyang Industrial, no filing with Korea's PIPC or KISA, and no national CERT advisory in the record. What follows is a well-corroborated criminal claim, not a confirmed forensic finding, and the reader should hold it at that weight.

What Happened

Accounts differ on when this started, and the divergence is worth stating plainly rather than smoothing over.

Ransomware.live records the victim as discovered on 2026-08-06 at 08:32 UTC with an estimated attack date of 2026-08-05. Cyberthreatintelligence.net gives the same disclosure date of August 6, 2026. DeXpose published its incident writeup on August 7 referencing an August 6 claim. Security Arsenal's monitoring, published August 6, places Namyang inside a cluster of four Barracuda victims posted across a 48-hour window from August 5 to August 6, spanning China, the United States, and South Korea.

Against that, a second wave of reporting is dated August 23. Undercode News, citing a ThreatMon alert, reports Barracuda adding Namyang Industrial to its victim list at approximately 10:07:20 UTC+3 on August 23, seconds before a second alert naming U.S. dental practice Skyline Implants & Periodontics. HookPhish logs a discovery timestamp of 2026-08-23T07:07:20 UTC, which is the same moment expressed in UTC. Brinztech, publishing August 23, frames the event not as a new listing but as an escalation: a dataset previously listed for sale that has now been "published" and "distributed freely on underground channels."

Undercode itself flags the tension, noting that public ransomware tracking data already tied both organisations to Barracuda around August 5 and 6, which makes the August 23 alert "less like the discovery of two completely new victims and more like a renewed signal surrounding an already observed Barracuda campaign." The most coherent reading of the full source set is a single intrusion claimed in early August, re-surfaced on August 23 when the extortion status flipped. The listing status supports that: ransomware.live and DeXpose both quote the posting as "Status: selling | Starting at $40000.00," while HookPhish's later capture of the identical posting text reads "Status: free | FREE."

There is also an unresolved discrepancy on the target domain. Brinztech, cyberthreatintelligence.net, DeXpose, and ransomware.live all cite nynexmo.com. HookPhish lists nyi.co.kr. Both appear to be legitimate Namyang properties, but no source reconciles which one the actor actually named.

What Was Taken

The volumetric claim is one of the few figures every source agrees on, which is unusual and reflects that they are all quoting the same verbatim leak-site post rather than independently counting: 17,641,181 lines in CSV format, 2.51 GB compressed size. No source reports having validated the dump contents against Namyang systems.

The actor's own description lists "information about employers, manufacturing, parts, clients, partners and etc." Brinztech's analysis of the dump expands this into four buckets: structured tabular records extracted from internal database tables rather than scraped web assets; proprietary manufacturing workflows, parts specifications, engineering parameters, and plant logistics; internal staff profiles; and client directories plus third-party business partner associations.

That last category is the one that should worry defenders outside Namyang. A 17.6 million row database of an industrial supplier's parts, clients, and partners is a supply-chain targeting package. It hands downstream attackers a mapped view of who buys what from whom, which is precisely the reconnaissance normally requiring weeks of effort. Note the sensitivity gradient: engineering parameters and parts specifications are commercial IP with a long half-life, while personnel records carry personal-data exposure that may trigger obligations under Korea's PIPA regardless of whether the company acknowledges the incident.

Row count is not record count. A 17.6 million line CSV export can represent far fewer distinct entities once transaction logs and junction tables are accounted for, and no source in this set makes that distinction. Treat 17.6 million as the actor's advertised figure, not a person count.

Why It Matters

Three structural points come out of this incident.

First, the pricing tells a story. Ransomware.live and DeXpose both record an asking price starting at $40,000. Security Arsenal assesses Barracuda's typical demands at USD $250K to $3M scaled to victim revenue, with smaller healthcare and dental victims at the $100K to $500K end. A $40,000 opening ask for a 2.51 GB industrial database sits well below the group's own floor, and the subsequent drop to free is the standard terminal move when a victim declines to negotiate. If that reading holds, Namyang did not pay, and the free release is the punitive stage of a double-extortion cycle that has already failed commercially.

Second, this is an emerging-actor problem. Ransomware.live explicitly labels Barracuda a "New Group" and warns the claim "should be treated with caution until independently verified." Cyberthreatintelligence.net gives internally inconsistent victim counts within a single page, stating both "4 victims since August 2026" and "5 confirmed victims globally," which is a good illustration of aggregator data quality at this stage of an actor's lifecycle. Security Arsenal notes the name itself is likely deliberate: there is no confirmed overlap with Barracuda Networks the security vendor, and the collision is assessed as an intentional confusion tactic. Expect that to poison keyword-based alerting and internal ticket triage.

Third, manufacturing remains the preferred target class for a reason that has nothing to do with data value. Both Security Arsenal and cyberthreatintelligence.net make the same point: production downtime converts to loss immediately, which compresses the victim's decision window and raises payment probability. Manufacturing made up 50% of Barracuda's August 5 to 6 posting wave.

The Attack Technique

No source establishes the intrusion vector with forensic evidence. What exists is correlation, and it points consistently in one direction.

Ransomware.live's page carries HudsonRock infostealer telemetry for the victim's domain showing 10 compromised employees, 5 compromised users, 6 third-party employee credentials, and an external attack surface of 12. Brinztech goes further, reporting that credentials tied to Namyang's self-managed IT infrastructure, specifically Keycloak single sign-on providers, corporate VPN gateways, and HR portals, appeared in infostealer logs prior to the ransomware deployment. That Keycloak and VPN detail comes from a single non-primary source and is not corroborated elsewhere in this set. It is plausible and it fits the HudsonRock counts, but it should be treated as a reported lead rather than an established fact.

Security Arsenal's actor profile describes Barracuda as an assessed RaaS operation with affiliate-driven intrusions and core-operator-run leak and negotiation infrastructure. Its listed initial access methods are edge device exploitation against VPN gateways and firewalls, exposed RDP, phishing with macro-enabled documents, and abuse of ScreenConnect-class RMM tooling. The same briefing names Check Point Security Gateways, Cisco FMC, Microsoft Exchange, and ConnectWise ScreenConnect as products warranting immediate patching and hunting attention.

Infrastructure fragments from ransomware.live: the domain resolves mail through mailfilter.nynexmo.com, publishes an SPF record of v=spf1 ip4:52.231.104.56 -all (an Azure Korea Central address range), and shows Microsoft 365 in use alongside self-managed components. That hybrid posture, cloud identity next to self-hosted SSO and VPN, is exactly the seam where infostealer-harvested credentials tend to survive undetected.

The honest summary: infostealer-sourced credential reuse against externally reachable identity infrastructure is the most probable vector on the evidence available, and it is unproven.

What Organizations Should Do

  1. Hunt your own domain in infostealer corpora, not just breach dumps. The HudsonRock counts here (10 employees, 6 third-party credentials) are the kind of signal that is available before an intrusion, not after. Query commercial stealer-log feeds for corporate domains, subsidiary domains, and contractor domains, and force resets on every hit regardless of apparent staleness.
  2. Enforce phishing-resistant MFA on Keycloak, VPN, and HR portals specifically. Self-managed SSO is the recurring weak point in this pattern. Password-plus-OTP does not survive a session-cookie theft; FIDO2 or certificate-bound authentication does. Audit which externally reachable applications still accept a password alone.
  3. Patch and hunt across the named edge stack. Per Security Arsenal, prioritise Check Point Security Gateways, Cisco FMC, Microsoft Exchange, and ConnectWise ScreenConnect. Then go further than patching: assume prior compromise on any device that ran a vulnerable version, and hunt for persistence and rogue local accounts.
  4. Constrain and monitor RMM tooling. ScreenConnect-class agents are a documented Barracuda access path. Allowlist the RMM products your organisation actually uses, block execution of all others, and alert on first-seen RMM binaries in the environment.
  5. Instrument for bulk database egress, not just file encryption. A 2.51 GB structured export leaving the network is the detection opportunity that precedes the ransom note by days or weeks. Alert on anomalous read volume against ERP, MES, and PLM databases, on unusual service-account query patterns, and on large outbound transfers to cloud storage or file-transfer services.
  6. Third parties named in this dump should act now. If your organisation is a Namyang customer, supplier, or partner, assume your contact records, contract terms, and parts specifications may be in the leaked set. Rotate any shared credentials or API keys, brief procurement and finance teams on targeted BEC risk, and raise scrutiny on invoice and bank-detail change requests referencing Namyang.

A closing caution echoed by Undercode News and ransomware.live alike: a leak-site listing is an allegation until the affected organisation, investigators, or forensic evidence confirm it. Namyang Industrial has not publicly responded. This brief should be read as an assessment of a criminal claim that is consistent across eight independent trackers, and it should be revised the moment a primary source speaks.

Sources: Barracuda Ransomware Syndicate Publicly Leaks 17.6 Million Records... | Namyang Industrial Co., Ltd. \ NAMYANG NEXMO Ransomware Attack by B... | Eclipse and Barracuda Ransomware Expand Their Victim Lists, With Cr... | Barracuda Ransomware Claims Two New Victims, Raising Fresh Concerns... | BARRACUDA Ransomware Gang: 4 New Victims Posted in 48 Hours — Manuf... | Barracuda Ransomware Attack Targets Namyang Industrial Co., Ltd. -... | Ransomware.live - Victim: Namyang Industrial Co., Ltd. \ NAMYANG NEXMO | Ransomware Group Barracuda Hits: Namyang Industrial ...