RANSOMWARE VICTIMDUPLICATE CLAIM

Sungwoo Co., Ltd

win.beast📍 South Korea (KR)📅 February 24, 2026
5
same group

Attack Intelligence

Sungwoo Co., Ltd was compromised in a ransomware attack attributed to win.beast in February 2026. The organization, operating in an undisclosed sector in South Korea, was added to the group's data leak site as part of an extortion campaign.

win.beast operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Overview: Sungwoo Co., Ltd. is a South Korean manufacturer primarily engaged in the production and sale of secondary battery components (rechargeable batteries). Key Products: The company specializes in safety components for lithium-ion batteries, such as Top Cap Assemblies, which prevent explosions by venting gas and cutting off current during overcharging. They also produce precision electrical parts for mobile devices (like wireless earphones) and electric vehicles (EVs). Market Position: Founded in 1992 and headquartered in Gumi, the company serves as a key supplier in the EV and consumer electronics supply chain. It was recently listed on the KOSDAQ exchange (Ticker: 458650)

Additional Details

data_size
200GB

Other Victims — win.beast (5)

Quick Facts

CountrySouth Korea (KR)
Attack DateFeb 24, 2026
StatusDUPLICATE CLAIM

Threat Group

win.beast
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.