Ransomware victim disclosure
← All victimsKelington Engineering Singapore Pte Ltd
Claimed by Nightspire · listed 9 days ago
Status timeline
- ListedJun 6, 2026
Current state: Listed for ransom
At a glance
- Group
- Nightspire
- Status
- Listed for ransom
- Country
- Singapore
- Sector
- Engineering
- Listed on leak site
- Jun 6, 2026
- Data size
- 600 GB
About the victim
AI dossier — public-source company profileKelington Group Berhad, established in 1999 and listed on Bursa Malaysia in 2009, provides integrated engineering services including UHP delivery systems for semiconductor/electronics, process engineering for petrochemical/industrial sectors, industrial gases manufacturing and trading, and general contracting. The Singapore Pte Ltd subsidiary operates as part of this broader engineering conglomerate.
- Industry
- Engineering Services & Industrial Gases
- Address
- Singapore
- Founded
- 1999
Attack summary
Severity: high — Confirmed exfiltration of significant business data (financial, technical, project IP) at substantial scale (600 GB) from a publicly listed engineering firm serving critical sectors (semiconductors, petrochemical). Technical project data and financial records represent material business and competitive harm.NIGHT SPIRE claims to have exfiltrated financial data and technical documents from Kelington Engineering Singapore Pte Ltd, including projects referenced as EMR_40111, EMR_alpha, EMR_BIOPSY, YiiEMR, and GNO. No ransom demand is stated; the 600 GB dataset is listed on the group's leak site.
Data the group says was taken
AI dossier — extracted from the leak post- Financial data
- Technical documents
- Project files (EMR systems, YiiEMR, GNO)
- Engineering designs and drawings
- Business contracts and invoices
- HR and employee records
The leak post
captured from the group's site- Financial Documents- HR Data- Supervisor's Information Data is not available now. Data is not available now. Data is not available now. [la familia adualt day center](http://www.lafamiliaadultdaycenter.com) Data is not available now. Data is not available now. - QuickBooks Files- Scanned tax returns- Proposal, Contrats- QuickBooks automated backups - Banking & Financial Records- Personal data- Critical POS Data - Banking & Financial Data- Accounting & Tax Records - Financial & Accounting Records- Human Resources- Sales & Marketing - Sales Related Documents- Human Resources- Sensitive Employee Records- Email and SMS Data Data is not available now. - Technical Documents- Financial Sheets- Contracts & Invoices- Business strategy files - MSSQL-DB- HR Documents- Contracts Data is not available now. [Progressive Oral Surgery & Implantology](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/progressiveoralsurgery.com) - Patients Information Records- Financial Records [The Country Club of Darien](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/CCDarien.org) - Sales / agent / commercial operations- Industrial / manufacturing / tooling business dat…
Data the group says was taken
- Financial Data
- Technical Documents Projects including EMR_40111, EMR_alpha, EMR_BIOPSY, YiiEMR, GNOB, MHA, mtbc
Screenshot of the leak post

Sources
Source
Indexed 9 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

