DAOR E&C Co., Ltd Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
DAOR E&C Co., Ltd was listed by the Qilin ransomware group on August 20, 2025, after internal files were exfiltrated in a ransomware attack; the number of individuals affected has not been disclosed. Anyone who has shared personal or business information with the company should review their accounts for unusual activity and consider protective steps such as changing passwords or enabling multi-factor authentication.
On 20 August 2025, the ransomware group known as qilin listed DAOR E&C Co., Ltd on its leak site, claiming to have exfiltrated internal files from the South Korean construction firm. The number of people whose information may be involved remains unknown, and public detail about the precise contents of those files is limited. For employees, contractors, partners or others whose records sit inside a construction company’s systems, the practical stakes are straightforward: once internal material leaves an organisation’s control, it can be used for fraud, social engineering or further targeting long after the initial incident fades from view.
What is confirmed so far is the listing itself and the claim of data theft in a ransomware attack. Everything else—scale, method of entry, and exact data categories—has not been publicly detailed. That uncertainty does not reduce the need for clear information about what is known and what people can usefully do next.
Breaking down the breach
According to the available record, DAOR E&C Co., Ltd was listed by the qilin ransomware group on 20 August 2025. The group asserts that internal files were exfiltrated during a ransomware attack. No figure has been released for the number of individuals affected, and no technical timeline, entry vector or ransom demand has been disclosed in the public summary. The only data description provided is the broad statement that internal files were taken.
Because the listing originates from the threat actor’s own site, it remains an unverified claim until independently confirmed. No additional breach metrics—file counts, volume of data, or specific systems compromised—appear in the reported facts. In short, the incident is publicly known only through the group’s assertion and the date of the listing; the rest is undisclosed.
The group behind it: qilin
Qilin is a ransomware operation that has operated as a ransomware-as-a-service model, recruiting affiliates to carry out intrusions while the core group supplies the encryptor and leak infrastructure. Like many contemporary ransomware crews, it typically follows a double-extortion pattern: data is stolen before encryption, and the threat of public release is used to pressure the victim. The group maintains a dark-web leak site where it posts victim names and, in some cases, samples of stolen material if negotiations stall.
Public reporting over recent years has associated qilin with attacks across multiple sectors and regions, often targeting mid-sized and larger organisations that hold operational or commercial data of value. Affiliates commonly gain initial access through phishing, compromised remote-access credentials or unpatched internet-facing systems, then move laterally to locate and stage data for exfiltration. None of these general tactics has been confirmed as the method used against DAOR E&C; they simply describe how the group is known to operate. In this case the only specific claim is the listing of the company and the assertion that internal files were taken.
About DAOR E&C Co., Ltd
DAOR E&C Co., Ltd is a South Korean company specialising in the production and construction of concrete structures. Its work includes concrete bridges, large cable-stayed bridges, liquefied natural gas tanks, underground tunnels and heavy lifting structures. The firm has more than four decades of experience in these fields. Organisations of this type sit at the intersection of civil engineering, industrial construction and critical infrastructure projects.
A company engaged in major civil works typically maintains detailed project documentation, engineering drawings, supplier and subcontractor records, employee and contractor personal data, financial information and correspondence with public or private clients. Because many of its projects involve large-scale infrastructure, the data it holds can be commercially sensitive and, in some cases, relevant to public safety or national infrastructure. A breach at such an organisation therefore carries consequences beyond ordinary commercial loss: it can affect project partners, workers on site, and the integrity of ongoing construction programmes.
The information in question
The only description given in the public record is that internal files were allegedly exfiltrated. No further breakdown—whether the material includes personal identifiers, payroll data, engineering plans, contracts or credentials—has been disclosed. Exact contents therefore remain unconfirmed.
Construction and engineering firms of this scale commonly store employee and contractor personal details, bank and tax information, project schedules, technical drawings, supplier agreements and internal communications. Any of those categories could be present among “internal files,” but it would be inaccurate to treat them as established facts for this incident. Until more precise inventories are released by the company or by independent investigators, the safest statement is that the nature and sensitivity of the stolen material are not yet publicly known.
What's at stake
For individuals whose data may sit inside the exfiltrated files, the concrete risks include identity fraud, targeted phishing that references real projects or colleagues, and the long-term reuse of personal or financial details. Even when personal data is not the primary target, internal documents can supply enough context for convincing social-engineering attacks against staff, partners or clients.
For the organisation itself, the stakes include operational disruption, potential regulatory scrutiny under Korean data-protection rules, contractual liabilities toward clients and partners, and the reputational cost of having internal material appear on a criminal leak site. Because DAOR E&C works on large infrastructure projects, any leakage of technical or commercial information could also affect competitive positioning and project security. None of these outcomes is guaranteed; they simply represent the ordinary range of consequences that follow ransomware claims of this kind when internal files leave an organisation’s control.
What to do if you're exposed
If you have reason to believe your information may have been held by DAOR E&C Co., Ltd—whether as an employee, contractor, supplier or project partner—begin with basic hygiene: monitor bank and credit accounts for unexpected activity, treat unsolicited emails or calls that reference the company with caution, and change passwords on any accounts that reused credentials linked to work email. Consider placing a fraud alert with credit agencies if personal identifiers are likely involved. Keep records of any suspicious contact that appears to draw on internal knowledge of the firm.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay alert for official statements from the company; until more detail is released, treat every claim about the stolen files as provisional and act on the practical precautions above.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Yooshin Engineering Corporation Listed by qilin Ransomware GroupDom Development Listed by qilin Ransomware GroupDolan Construction Listed by qilin Ransomware GroupSTIC Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the DAOR E&C Co., Ltd Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.