dystar.com
Attack Intelligence
dystar.com was compromised in a ransomware attack attributed to settra in June 2026. The organization, operating in the Manufacturing sector in Singapore, was added to the group's data leak site as part of an extortion campaign.
settra operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
1.3 terabytes of data — from a company that manufactures dyes for the global textile industry. Inside: financial reports and AR registers. Budget letters with instructions for global controllers. Technical specifications for cloud systems. Employee lists with Microsoft 365 account identifiers. Banking details belonging to the company itself and its clients. Board of directors minutes. OSHA inspection records and complaints from neighboring residents. Lists of active litigation across six countries. Records of government subsidies. All of it — internal documents belonging to DyStar, a global manufacturer of textile dyes headquartered in Singapore. This article contains only a portion of the data we have chosen to disclose. Everything else will be available to download and review independently once the full archive is released.