On 15 September a ransomware crew calling itself MetaEncryptor added Nippon Steel Corporation, Japan's largest steelmaker, to its data leak site, alongside the South Korean industrial equipment maker SFA Engineering. Three weeks earlier the biggest name on that same site was a Canadian consumer products supplier.
None of it is confirmed. That is the normal state of a leak site listing, and it is the first thing to hold on to here.
Three posting days, and the names keep growing
IntelFusions has logged 13 claims from MetaEncryptor, every one of them since 23 August, and they arrived in three distinct batches. On 23 August the crew named seven organizations, none of them household names: a Canadian consumer products supplier, a US trucking company, a water sector supplier, a German pharmaceutical firm, a seafood producer and two manufacturers. On 7 September it named four, and the profile shifted sharply. Those four were the Canadian construction group EllisDon, the Singapore engineering and defence group ST Engineering, the US medical device maker Hologic, and the American manufacturer SIFCO Industries. On 15 September it named two, and both were large Asian industrial manufacturers.
Fewer names each time. Bigger names each time. That is the observation, and it is the only thing the data supports on its own.
Who MetaEncryptor is, as far as anyone knows
IntelFusions tracks MetaEncryptor as a double extortion ransomware operation first observed in mid-2023, carrying LostTrust among its aliases, and historically pointed at medium to large enterprises in legal, technology, logistics, manufacturing and finance across the UK, Europe and South East Asia. WatchGuard's ransomware tracker entry classifies it the same way, as a crypto ransomware operation that runs direct and double extortion and publishes free data leaks.
Our incident dataset for this crew begins on 23 August, so how long the name sat idle before that is not something we have measured, and it should not be reported as though it were.
What a listing is and is not
A data leak site entry is a negotiating instrument. The crew decides what appears on it, when it appears, and whether the data it describes exists in the form claimed. Entries get recycled from other crews' intrusions, padded, or posted against a supplier when the brand the crew actually wants to pressure sits one step away. Nippon Steel, SFA Engineering, ST Engineering, Hologic, SIFCO and EllisDon have published nothing to confirm any of this, and until one of them does, the accurate description is that a criminal group has made an assertion.
What is checkable is the shape of those assertions, and the shape changed. Asia has carried a steady share of leak site activity all quarter, and Japan has had a bruising few weeks already, including a month of hacktivist traffic floods and genuine intrusions. The longer picture sits on our Japan country profile.
There is no patch here, only a watch list
Nothing in this story has a fix to apply, which is exactly why it is easy to put down. The useful response is procedural. If your organization is on that list, or supplies someone who is, assume the question is coming and have an answer ready before a customer asks it. If it is not, the value is in the direction of travel: a crew that has reached progressively larger targets three times running is more likely to try a fourth than to stop, and the ground it has covered so far is heavy manufacturing, construction, medical devices and defence engineering.
The thing to watch now is who speaks. A confirmation, a regulatory filing, or a silence that stretches past a few weeks will each tell you something different about how much of this was ever real.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.