On May 21, 2026, the safepay ransomware group listed iql-nog.com on its leak site and claimed to have exfiltrated internal files from the company in a ransomware attack. The incident affects anyone whose personal or employment data was stored in those systems, including employees, customers, and business partners whose information may now sit in the hands of extortionists.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch iql-nog.com
Get alerted the next time iql-nog.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about iql-nog.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that iql-nog.com, a company founded in 1947 and focused on oleochemical products such as fatty acid esters and specialty chemicals, was targeted in a ransomware operation. The attackers posted details on their leak site hosted at a Tor onion address, claiming successful data exfiltration. No exact victim count has been released, and the precise volume or types of records taken remain unclear from available reporting. The listing appeared on May 21, 2026, following the group’s typical pattern of publishing stolen material when ransom demands go unmet.
Why This Matters for You and Your Family
When a company’s internal files are stolen, the information often includes employee records, vendor contracts, customer details, or correspondence that can contain names, addresses, dates of birth, Social Security numbers, or email accounts. If you or a family member ever worked at the company, purchased its products, or had your information shared in its supply chain, that data could surface in future leaks or be sold quietly on underground forums. Credential leaks like this one frequently cascade into account takeovers elsewhere because people reuse the same passwords across services. Children’s accounts tied to family emails are especially vulnerable once a parent’s work data is exposed.
The Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers or buyers can combine them with other publicly available records to build detailed profiles. A work email from the breach can be linked to personal social-media handles, gaming usernames, or family addresses. This creates an identity chain that makes doxxing, targeted phishing, or harassment far easier. Public reporting describes how such chains often begin with one corporate breach and expand rapidly when criminals cross-reference the new data against existing leaks. Gaming accounts belonging to you or your children are frequent secondary targets because they frequently share the same email addresses or recovery phone numbers found in work-related files.