LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › International Chemical Co. Listed by Barracuda Ransomware Group

HIGH severityUnverified claimHow we verify

International Chemical Co. Listed by Barracuda Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 26, 2026
International Chemical Co. Listed by Barracuda Ransomware Group

Reported September 26, 2026.

HIGH
Severity
September 26, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

International Chemical Co. was listed by the Barracuda ransomware group on September 26, 2026, with the group claiming to hold data belonging to an undisclosed number of people. Individuals should check any accounts or services linked to the organisation and consider protective steps such as monitoring for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to pressure companies by posting alleged victims on leak sites, often before any independent confirmation exists. Listings can mix real intrusion claims with recycled material or exaggeration, and they are written to create urgency for payment or competitive interest.

On September 26, 2026, the Barracuda ransomware group listed International Chemical Co. on its leak site. The company has not publicly confirmed the claim as of writing. What follows treats the post as an unverified claim, explains what such a listing does and does not establish, and outlines conditional steps readers can take if they believe their information could be involved.

What is being claimed

Barracuda has listed International Chemical Co. (also referred to in the listing material as International Chemical Company, or ICC) and describes the matter at high severity. According to the listing, the group claims to have taken material from the company’s main file server, states a volume of about 90 GB, marks the status as selling, and associates a figure rendered as $50,00 in the available record. The number of people affected is unknown in the public listing detail.

The group’s own summary claims possession of data touching sales, formulas, patents, manufacturing, contracts, and partners. It further claims, as an example, full formulation and manufacturing instructions for a patented product described as I.C.C.’s Biodraulic hydraulic oil, and states that material is available for sale to competitors. Method of intrusion, exact timing of any alleged access, and independent verification of the files are not established in the facts available here. Public detail beyond the leak-site claims is limited.

A leak-site entry is a pressure tactic. It does not, by itself, prove what was copied, whether the sample descriptions are accurate, or whether the company has validated any loss. Until the organisation or a regulator confirms otherwise, the responsible reading is that Barracuda has made these assertions and is marketing alleged data for sale.

The group behind it: Barracuda

Barracuda is known publicly as a ransomware and extortion-style actor that pairs encryption or data theft claims with leak-site publication. Groups in this category typically threaten to publish or sell stolen material if demands are not met, use countdown-style pressure, and advertise alleged corporate archives to competitors or other buyers. Their posts often emphasise intellectual property, commercial contracts, and internal documents because those categories can raise both operational and competitive stakes for industrial firms.

Well-documented patterns for such crews include double-extortion messaging—claiming both disruption and data exposure—and staged releases or “proof” samples meant to convince victims and third parties that the haul is real. None of that general pattern proves the accuracy of any single listing. For this case, only the claims attached to the International Chemical Co. entry should be treated as specific: the group claims extraction from a main file server, names broad commercial and technical categories, cites roughly 90 GB, and presents the material as for sale. No confirmed victim statement is included in the facts provided.

About International Chemical Co.

International Chemical Co. is described in the listing-related summary as a manufacturer of specialty metalworking fluids, industrial cleaners, rust preventatives, and custom chemical formulations. Its public-facing site is associated with e-icc.com in the available record. Firms in specialty chemicals and industrial fluids typically sit at the intersection of manufacturing know-how, customer supply relationships, and regulated product handling.

A credible compromise of such an organisation would matter because the sector often depends on proprietary formulations, process instructions, quality records, and long-running commercial agreements. Customers may include manufacturers that rely on stable supply and consistent product performance. Even an unconfirmed listing can create uncertainty for partners who must decide how to treat outbound claims about formulas and contracts. That uncertainty is a reason to watch for official company or regulator statements rather than to treat the leak site as a final inventory.

What was likely exposed

The facts do not provide a confirmed inventory of exposed personal data types. Named categories in the attacker’s marketing language include sales information, formulas, patents, manufacturing material, contracts, and partner-related data, with a specific claim about formulation and manufacturing instructions for a patented Biodraulic hydraulic oil. Those descriptions remain the group’s claims, not a verified file list.

If files of the kind the listing advertises were taken, organisations in specialty chemicals commonly hold some mix of the following: product recipes and process parameters; patent and intellectual-property files; manufacturing and quality documentation; customer and supplier contracts; pricing and sales records; and business-contact details for partners and staff. They may also hold credentials or system documentation adjacent to file servers, though nothing in the facts confirms that here. Exact contents, whether personal data of individuals was included, and whether the advertised 90 GB set is complete or accurate are unconfirmed.

Readers should not assume that any particular document or personal record is in circulation solely because a crew named those themes. Conditional risk assessment—if commercial or technical files were copied—is the limit of what the public listing supports.

The real-world impact

For the organisation, an extortion listing that advertises formulas, patents, and contracts can threaten competitive position if genuine trade secrets were involved, complicate customer trust, and create legal and disclosure questions under applicable contract and privacy rules. Because the incident is unconfirmed publicly, the immediate impact may include reputational pressure and partner inquiries driven by the claim itself, separate from any proven theft.

For individuals who interact with the company—employees, contractors, or business contacts—the practical risk depends on whether personal or contact data sat on systems the group claims to have accessed. If such data were included, typical concerns would include targeted phishing that references real commercial relationships, social engineering against partners, and misuse of email addresses or phone numbers. If only technical and commercial files were involved, direct consumer identity theft risk could be lower, while competitive and contractual harm could still be significant for the business and its counterparties.

None of these outcomes is established as fact by the listing alone. Scale of human impact remains unknown. Severity labelled “HIGH” on a leak site reflects the actor’s framing, not an independent assessment.

If your data was involved

If you have a relationship with International Chemical Co. and worry that your information could appear in material the group claims to hold, treat the situation as conditional. Watch for official notices from the company. Be wary of unexpected messages that cite contracts, orders, or chemical products to push you toward links or payments. Prefer verified channels when confirming any request that involves credentials, banking, or sensitive documents.

Consider standard account hygiene where relevant: unique passwords, multi-factor authentication on email and work systems, and careful review of financial or procurement accounts tied to the business relationship. If you are an employee or partner, follow your organisation’s incident and IT guidance rather than instructions from unsolicited third parties.

You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach datasets, which may help you prioritise monitoring even when a specific incident remains unconfirmed. Public detail on this listing is limited; confirmation, scope, and any individual notification duties rest with the company and authorities if and when they speak.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyInternational Chemical Co. security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See International Chemical Co.’s full breach history →

More recent breaches

Namyang Industrial Co., Ltd. Listed by Barracuda Ransomware GroupAugust 23, 2026i2i-systems Listed by Barracuda Ransomware GroupSeptember 13, 2026Namyang Industrial Co., Ltd. \ NAMYANG NEXMO Listed by Barracuda Ransomware GroupAugust 6, 2026RS Automation Co., Ltd. Listed by Barracuda Ransomware GroupAugust 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the International Chemical Co. Listed by Barracuda Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by barracuda — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram