Ransom! SFA Engineering

SFA Engineering, based in South Korea, was targeted by the underground threat actor in a ransomware attack that compromised 2.3 terabytes of industrial data, leading to significant operational disruption. The ransomware incident is believed to be part of a larger schema generating an estimated revenue of $1.7 billion, impacting South Korea. #SouthKorea

Incident Details

  • Victim: SFA Engineering
  • Country: KR
  • Actor: underground
  • Source: http://47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion/packages/3d8a47a4-988b-4842-844a-047a3f1f9e9d
  • Discovered: 2025-08-15 14:03:57.684917
  • Published: 2025-08-15 12:48:00.000000

Information

  • Ransomware victim: SFA Engineering
  • Country: South Korea (KR)
  • Perpetrator: Underground group
  • Revenue: $1.7 billion
  • Type: Industry sector
  • Data size: 2.3 Terabytes

Disclaimer: This post is based on public claims made by the ransomware group "underground". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live