RANSOMWARE VICTIMMANUFACTURING

dystar.com

settra📍 Singapore (SG)📅 June 26, 2026
8
same group

Attack Intelligence

dystar.com was compromised in a ransomware attack attributed to settra in June 2026. The organization, operating in the Manufacturing sector in Singapore, was added to the group's data leak site as part of an extortion campaign.

settra operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

1.3 terabytes of data — from a company that manufactures dyes for the global textile industry. Inside: financial reports and AR registers. Budget letters with instructions for global controllers. Technical specifications for cloud systems. Employee lists with Microsoft 365 account identifiers. Banking details belonging to the company itself and its clients. Board of directors minutes. OSHA inspection records and complaints from neighboring residents. Lists of active litigation across six countries. Records of government subsidies. All of it — internal documents belonging to DyStar, a global manufacturer of textile dyes headquartered in Singapore. This article contains only a portion of the data we have chosen to disclose. Everything else will be available to download and review independently once the full archive is released.

Additional Details

Other Victims — settra (8)

Quick Facts

CountrySingapore (SG)
SectorManufacturing
Attack DateJun 26, 2026
Intel Sourceransomlook

Threat Group

settra
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.