Redpacketsecurity [SHINYHUNTERS & DOOMMAGEDDON] Ransomware Attacks Target Kimberly-Clark and INCOR Group
Article Content
- •Kimberly-Clark and INCOR Group are reported ransomware victims as of September 13, 2026.
- •Both attacks are unverified, lacking evidence of data exfiltration or operational impact.
- •Deadlines for response are set for September 16 and September 20, 2026, respectively.
On September 13, 2026, two companies, Kimberly-Clark and INCOR Group, were listed as victims of ransomware attacks by the SHINYHUNTERS and DOOMMAGEDDON groups, respectively. Kimberly-Clark, a U.S.-based manufacturing company, received a final warning from SHINYHUNTERS, demanding action by September 16, 2026, although no confirmed intrusion date or details on data exfiltration were provided. Similarly, INCOR Group was listed by DOOMMAGEDDON with a deadline of September 20, 2026, but lacked specifics on the nature of the attack or any ransom demand. Both listings are considered unverified and lack evidence of successful data breaches or operational impacts. The situation remains fluid, with both companies urged to respond to avoid further digital disruption. Currently, no details on the type of data involved or the attack vectors are available, making the threat assessment challenging.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Doommageddon, ShinyHunters and Incor Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…