Metals

Industry

Japanese Aluminum Manufacturer Operations Impacted by Cyberattack

October 1, 2025

Manufacturer Mino Kogyo Co., Ltd. confirmed a cyberattack and its details on their website. The company detected the attack and initiated a network shutdown on October 4, 2025. Production activities were partially affected but largely continued through individual adjustments. Financial settlement systems were restored quickly. The company later confirmed 300 GB of communications data had been stolen.

SafePay claimed responsibility for the attack. The hackers got access through a regular employee’s VPN account using a valid ID and password (not a VPN vulnerability exploit). This led to internal exploration, system administrator privilege escalation (Oct 3), system destruction, and file encryption. Data leak was confirmed on October 28, 2025.

read more

Cyberattack at Metal Finishing Company

November 19, 2024

Purecoat International, LLC and its sister company Purecoat North suffered a cyberattack where attackers stole personal identifiable information in a data breach.

On January 13, 2025, Purecoat identified a cyber incident impacting certain of its systems. Through its investigation, Purecoat confirmed sensitive personal information in certain files in its network may have ended up viewed and obtained by an unauthorized third party between November 19, 2024, and January 12, 2025.

read more

Ransomware Attack at Soon Lian Holdings

July 3, 2024

Soon Lian Holdings announced they suffered a ransomware attack on the evening of July 3. The group said there has been no significant impact to its business operations and that it activated its business continuity plan immediately after.

read more

Cyberattack Affects All Locations of German VDM Steel

January 9, 2023

Unknown perpetrators carried out a cyberattack on VDM Metals. All locations are affected, including those in Werdohl (administration, wire and strip production), Altena (plate and rod production), Unna (melting plant, forge and rod finishing shop) and Siegen (plate rolling mill). Significant parts of the company’s IT infrastructure are affected. Production came to a standstill and parts of the workforce sent home.

Two weeks later production is gradually restarting. The problem seemed to lie in the logistics data flow. VDM communicates most parts of the business will be up and running again by next week.

Several hundred computers have been exchanged in the company. The plant uses server resources from the Spanish parent company Acerinox, as can be seen from the new e-mail addresses of the employees.

read more

Steel plant infected with Conficker

January 1, 2011

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Steel Plant infection with Ahack Worm

January 1, 2008

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Blaster Impacts HMI Stations in Smelter

January 1, 2003

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

11 Ethernet PLCs Fail At Once

January 1, 2003

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more