Welcome To ChemAnalyst
South African chemical manufacturer Isegen is investigating claims made by the notorious ransomware group DragonForce, which alleges it infiltrated the company’s systems and exfiltrated sensitive corporate data. Despite the cybercriminals’ assertions, Isegen stated that its internal investigation has so far found no evidence of unauthorized access, compromised systems, or stolen information.
According to the company, an immediate and comprehensive cybersecurity review was initiated after it became aware of online reports suggesting a possible breach. Isegen emphasized that its production facilities and business operations remain fully functional, adding that cybersecurity specialists continue to monitor the situation closely. The company also confirmed it would provide further updates should credible evidence of a breach emerge.
Isegen plays a critical role in South Africa’s chemical industry as the country’s sole producer of several key industrial chemicals. These include Phthalic Anhydride and Maleic Anhydride, both essential raw materials for alkyd resins and unsaturated polyester resins widely used in the paints, coatings, and composites sectors. The company is also South Africa’s exclusive manufacturer of fumaric acid, a specialty chemical extensively utilized in food and beverage applications, preservatives, bakery products, animal feed, and industrial printing inks.
Additionally, Isegen is the nation’s only producer of PVC plasticisers, which are vital for manufacturing flexible plastic products such as medical devices, PVC pipes, water hoses, and various consumer goods. Given its strategic position in multiple supply chains, any confirmed cybersecurity incident could attract significant attention across industrial markets.
DragonForce, operating under a ransomware-as-a-service (RaaS) model, claims it extracted approximately 234.63 GB of confidential data from Isegen’s internal systems. The group has threatened to publish the allegedly stolen information—including corporate correspondence, contracts, intellectual property, passports, and other sensitive documents—on 6 August 2026 unless its demands are met. The company first appeared on DragonForce’s dark web leak site on 14 July 2026.
DragonForce has emerged as one of the world’s most active ransomware organizations since 2023, initially targeting entities in the Middle East and Asia before expanding globally. The group frequently attacks government institutions and high-profile industrial companies, seeking financial gain through data encryption, extortion, and public disclosure of confidential information. It also claimed responsibility for the cyberattack on South Africa’s National Credit Regulator in late 2025. While DragonForce’s allegations have raised concerns, Isegen maintains that no verified breach has been identified, and investigations remain ongoing.
We use cookies to deliver the best possible experience on our website. To learn more, visit our Privacy Policy. By continuing to use this site or by closing this box, you consent to our use of cookies. More info.

Leave a Comment
Comments (0)