SFA Engineering, based in South Korea, was targeted by the underground threat actor in a ransomware attack that compromised 2.3 terabytes of industrial data, leading to significant operational disruption. The ransomware incident is believed to be part of a larger schema generating an estimated revenue of $1.7 billion, impacting South Korea. #SouthKorea
Incident Details
- Victim: SFA Engineering
- Country: KR
- Actor: underground
- Source: http://47glxkuxyayqrvugfumgsblrdagvrah7gttfscgzn56eyss5wg3uvmqd.onion/packages/3d8a47a4-988b-4842-844a-047a3f1f9e9d
- Discovered: 2025-08-15 14:03:57.684917
- Published: 2025-08-15 12:48:00.000000
Information
- Ransomware victim: SFA Engineering
- Country: South Korea (KR)
- Perpetrator: Underground group
- Revenue: $1.7 billion
- Type: Industry sector
- Data size: 2.3 Terabytes

Disclaimer: This post is based on public claims made by the ransomware group "underground". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.