RANSOMWARE VICTIMMANUFACTURING

doosan.com

settra📍 South Korea (KR)📅 June 26, 2026
8
same group

Attack Intelligence

doosan.com was compromised in a ransomware attack attributed to settra in June 2026. The organization, operating in the Manufacturing sector in South Korea, was added to the group's data leak site as part of an extortion campaign.

settra operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Over 3.2 terabytes of data. A complete digital snapshot of a corporate group that has spent decades manufacturing equipment that workers trust with their lives on construction sites around the world. Thousands of internal emails. Signed settlement agreements with suppliers covering every major defect. Financial statements from subsidiaries across eight countries. Payroll records. Bank account details in multiple currencies — and a full history of every time those details changed. Product line items under US export controls tied to chemical weapons non-proliferation. An internal support ticket asking: "Are we even still supplying the safety latch for the quick-coupler?" Complete engineering drawings and manufacturing tooling — hundreds of PDFs and original CAD files from which the product could be reproduced from scratch. Field modification and rework tools for known hydraulic defects — documented, signed, with tolerances measured in thousandths of an inch. Sixteen years of patent strategy: what the company patented, what it studied in competitors' work, which competitors it was preparing patent claims against — and a federal lawsuit filed against Bobcat itself. Personal data of US employees: Social Security numbers, payroll direct deposit bank accounts, medical records. This article contains only a portion of the data we have chosen to disclose. Everything else will be available to download and review independently once the full archive is released.

Additional Details

Other Victims — settra (8)

Quick Facts

CountrySouth Korea (KR)
SectorManufacturing
Attack DateJun 26, 2026
Intel Sourceransomlook

Threat Group

settra
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.