Ransomware victim disclosure
← All victimsMoen
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jan 15, 2026
About the victim
AI dossier — public-source company profileMoen Incorporated is a leading American manufacturer of faucets, showerheads, and other plumbing products headquartered in North Olmsted, Ohio. The company operates globally and is a subsidiary of Fortune Brands Innovations. Moen products are sold in residential and commercial markets across North America and internationally.
- Industry
- Plumbing Fixtures & Faucet Manufacturing
- Address
- 25300 Al Moen Drive, North Olmsted, OH 44070, United States
- Employees
- 1001-5000
- Founded
- 1937
Attack summary
Severity: high — Moen is a large, well-known manufacturing company and the disclosed status is 'data_published', indicating Qilin claims to have exfiltrated and released data. Even without explicit data inventory detail, confirmed publication by a known ransomware group against a company of this scale warrants a high severity rating.The Qilin ransomware group has listed Moen under a 'data_published' status, indicating claimed exfiltration and publication of company data. The leak post context is minimal and no specific data volume or ransom demand was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Potentially employee records
- Potentially financial records
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

