Ransomware victim disclosure
← All victimsSFA Engineering Corporation
Claimed by Metaencryptor · listed 15 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- South Korea
- Sector
- Manufacturing
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileSFA Engineering Corporation is a South Korean high-tech engineering company specializing in industrial automation, robotics, and manufacturing equipment. The company serves major global manufacturers in the semiconductor, OLED display, battery, and smart factory sectors.
- Industry
- Industrial Automation, Robotics & Manufacturing Equipment
Attack summary
Severity: low — Listing/announcement only with no proof files published, no confirmed data exfiltration, and no operational impact stated. Announcement alone without evidence does not constitute verified compromise.The metaencryptor group claims to have attacked SFA Engineering Corporation. No files have been published yet, and no details on encryption, exfiltration, or specific data compromised are provided.
What the group claims
SFA Engineering Corporation is a South Korean high-tech engineering company specializing in industrial automation, robotics, and manufacturing equipment. The company provides advanced solutions for the semiconductor, OLED display, battery, and smart factory industries, serving major global manufacturers.
The leak post
captured from the group's siteSFA Engineering Corporation is a South Korean high-tech engineering company specializing in industrial automation, robotics, and manufacturing equipment. The company provides advanced solutions for the semiconductor, OLED display, battery, and smart factory industries, serving major global manufacturers. Files for this campaign have not been published yet.
Sources
Source
Indexed 15 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

