The Anubis ransomware operation added global packaging manufacturer Scholle IPN / SIG (sig.biz) to its dark web victim list on August 18, 2026, alleging a data breach at what the group described as "a global leader in packaging manufacturing." The listing has been reported by DeXpose and, via ThreatMon monitoring feeds, by UNDERCODE NEWS. As of this writing there is no statement from SIG, no regulator filing, and no vendor or national CERT advisory naming the company. Every source covering this incident is OTHER-tier, and every one of them is describing the same single artifact: a leak site post. Treat it accordingly.
What Happened
The timeline available from monitoring feeds is narrow but consistent. ThreatMon reported that Anubis added Scholle IPN / SIG to its victim list at approximately 09:03:59 UTC+3 on August 18, 2026. Roughly thirteen minutes later, at approximately 09:16:39 UTC+3, a separate group tracked as AuditTeam listed an organization identified only as "Deup." Both UNDERCODE NEWS pieces (S4, S5) describe the same two entries and the same timestamps, so this is one report echoed twice rather than two independent confirmations.
DeXpose (S1) published its own writeup on August 19, recording the target as Scholle IPN / SIG, the domain as sig.biz, the country as USA, and the attributed group as Anubis, with the threat actor statement quoted as "Data breach at a global leader in packaging manufacturing."
There is a jurisdictional wrinkle worth flagging. DeXpose tags the victim as USA. Corporate profile data in S7 indicates Scholle IPN is headquartered in Northlake, Illinois, operates in nine countries with a workforce distributed across nineteen, and was acquired into SIG Group, which is headquartered in Switzerland and carries 4,000 to 5,000 employees. Scholle IPN alone is listed at 200 to 300 employees with annual revenue in the $500M to $600M range. Whether the intrusion touched the US subsidiary, the Swiss parent, or shared infrastructure across both is not established by any source. That distinction determines which breach notification regimes apply, and nobody has answered it publicly.
UNDERCODE NEWS is explicit on the evidentiary limits, and the caveat is worth repeating verbatim in spirit: the available reporting describes a ransomware group victim claim, not independently verified evidence that systems were compromised or data stolen. No source provides technical evidence of encryption, data theft, operational disruption, or unauthorized access.
What Was Taken
Nothing specific has been established. No source in this set provides a data volume, a record count, a file sample, a leak deadline, or a ransom figure for the Scholle IPN / SIG listing. The only characterization of the stolen material is Anubis's own one-line claim of "a data breach."
This is a genuine absence of information rather than a conflict between sources. There is no range to state here because no source states a figure at all. Any number circulating for this incident right now is not coming from the reporting available.
For calibration on how Anubis describes its own hauls, the group's July 2026 listing of Coca-Cola and its Fairlife dairy subsidiary claimed roughly 1 TB of exfiltrated data. SecurityWeek (S2) reports Coca-Cola subsequently confirmed the incident involved "the taking of certain data" without further detail, while UltraViolet Cyber (S6) reports Anubis went on to publish that data after the ransom deadline passed. SecurityWeek's own caution applies directly to the Scholle IPN / SIG claim: extortion gangs commonly exaggerate the importance of what they have taken in order to pressure victims.
Why It Matters
Anubis is the substantive part of this story, and it is well documented independent of the Scholle IPN / SIG claim.
UltraViolet Cyber assesses Anubis as a ransomware-as-a-service operation active since December 2024, when it emerged under the earlier test name "Sphinx" before rebranding. It runs an affiliate program on Russian-language cybercrime forums with negotiable revenue splits and multiple monetization paths beyond a straight ransom, including separate programs for data extortion and for access sales. SecurityWeek's count as of the Fairlife coverage put the group at roughly 100 listed organizations.
Two attributes make Anubis worse than a median RaaS crew. First, its encryptor carries an optional file-wiping capability, meaning files can be permanently destroyed even after encryption. UltraViolet Cyber's blunt framing is that backups alone will not save you, and that offline immutable backups are essential rather than optional. Second, its victimology spans unrelated sectors with no apparent geographic boundary, which points to opportunistic rather than targeted selection. No industry gets to assume it is a low-priority target.
The Fairlife case is the template for why a packaging manufacturer listing deserves attention. That intrusion hit a mid-sized subsidiary and produced enterprise-wide consequences: suspended US dairy production across four facilities, SEC disclosure, and ultimately confirmed data theft. Scholle IPN sits inside a comparable structure, a smaller acquired unit inside a much larger multinational parent, embedded in a food and beverage packaging supply chain. If the claim is real, the blast radius question is not "how big is Scholle IPN" but "what does Scholle IPN connect to."
The Attack Technique
No initial access vector has been reported for this specific incident. Nobody has published IOCs, a CVE, a compromised credential source, or a dwell time for Scholle IPN / SIG.
What is documented is Anubis's general tradecraft. UltraViolet Cyber identifies spear-phishing as the group's primary initial access method, making email and web filtering plus user training the frontline control, and flags privilege escalation activity as a subsequent stage to watch for. The group operates a double extortion model, encrypting files on compromised systems while exfiltrating data to increase leverage, per SecurityWeek. The optional wiper sits on top of that as a third pressure mechanism.
Applying that profile to this listing is inference, not attribution of technique. It is the reasonable prior for an Anubis intrusion, and it is where a defender at a similar organization should look first. It is not a finding about what happened at Scholle IPN.
What Organizations Should Do
- Harden against spear-phishing first. Anubis's documented entry point is email. Enforce MFA on all access points, tighten email and web filtering, and run phishing simulations against the populations that actually handle external correspondence, including customer service and procurement functions in packaging and logistics operations.
- Assume backups are a target, not a safety net. The wiper capability means encrypted-then-deleted is a realistic outcome. Move to offline, immutable, and independently credentialed backups, and test restoration rather than assuming it works.
- Hunt for privilege escalation and persistence now, not after an alert. If your organization sits in a supply chain adjacent to a claimed victim, run a compromise assessment covering how access could be obtained, what could be exfiltrated, and whether persistence mechanisms exist. DeXpose recommends the same sequence.
- Map subsidiary-to-parent trust relationships. Fairlife demonstrated that a smaller acquired entity can carry enterprise-wide consequences. Inventory shared identity providers, shared VPN and remote access, shared file shares, and any flat network paths between an acquired unit and the parent estate.
- Get the notification clock scoped before you need it. Per the compliance guidance in S8, GDPR requires supervisory authority notification without undue delay and where feasible within 72 hours of awareness, including the nature of the breach, approximate numbers of data subjects and records, DPO contact details, likely consequences, and mitigations. For a multinational with US and EU operations, that means clean discovery timestamps and a rapid fact classification process are prerequisites, not paperwork.
- Route any actor contact through counsel and professional IR. Engage incident response specialists and legal counsel before any dialogue with the group or with ransom brokers.
Assessment and Confidence
We rate this as an unconfirmed extortion claim, not a confirmed breach, and the distinction is load bearing.
Confidence is high that Anubis posted the listing: two independent publishers describe it, with a specific timestamp and a quoted actor statement. Confidence is low that a compromise of Scholle IPN / SIG systems occurred as described, because no primary source exists. No SIG statement, no regulator filing, no CERT advisory, and no vendor telemetry names this victim. The Trinetra ransomware tracker (S3) returned no incident-specific data for this listing at time of writing.
Anubis's track record cuts both ways here. The group followed through on Fairlife, publishing after the deadline lapsed, which raises the base rate that its claims are real. But an unfollowed-up leak site entry with no sample, no volume figure, and no countdown is also the exact shape of a claim that gets quietly withdrawn or that reflects access far shallower than advertised. The next verifiable signal will be either a SIG statement or the appearance of actual leaked files. Until one of those arrives, this brief is reporting on a post, and we are saying so.
Sources: Anubis Ransomware Attack on Scholle IPN / SIG - DeXpose | Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - S... | Trinetra Threat Intelligence Live global ransomware map | Anubis and AuditTeam Ransomware Claims Surface as New Organizations... | Two Ransomware Groups Add New Victims as Dark Web Activity Intensif... | Threat Advisory: The Ongoing Threat of Anubis Ransomware | Nanette Jones | Data Breach Notification: Executive Compliance Guide