A Massachusetts supplier of industrial cameras and machine-vision parts is the latest name on a ransomware leak site. Ransomware.live indexed Saber1 Technologies (saber1.com) as a claimed victim of the Deadlock ransomware group at 2026-10-09 22:51 UTC (about 6:51 p.m. ET Friday), with an estimated attack date of Oct. 9. ShellCodeX tracks the same listing and labels it an unverified claim.
Saber1's website describes a supplier and distributor of machine-vision gear: industrial cameras, CameraLink, CoaXPress and USB cables, lenses and filters, frame grabbers, lighting, and enclosures, from a long list of camera makers. It lists an address at 225 Stedman St. in Lowell, Massachusetts. The site was up (HTTP 200) when we checked Sunday morning.
What's claimed, and what's confirmed
Claimed: Deadlock has listed Saber1 on its leak site. The tracker carries a one-line company profile, but no file count, data size, record types, or deadline. That profile describes the business. It isn't evidence about the incident.
Tracker context, not incident facts: Ransomware.live's page for the domain flags past credential exposure. It shows 35 leaked passwords (six rated critical) from ParanoidLab, three compromised user and three third-party credentials from Hudson Rock, and a note that the domain's FortiOS SSL-VPN credentials appeared in the "FortiBleed" leak tied to CVE-2022-40684, a 2022 FortiOS flaw. That is background exposure data, not a cause. No source we read confirms how Deadlock got in, or that it got in at all.
Not confirmed: We found no statement from Saber1, no news coverage, and no breach filing. There is no confirmed encryption, no confirmed theft of customer or supplier data, no reported order or shipping disruption, and no word on payment. Treat it as a claim.
Why it matters to industrial shops and distributors
Distributors and value-added resellers sit in the middle of the supply chain. They hold customer quotes and pricing, OEM part numbers and specs, supplier contracts, and the email threads where purchase orders and payment details change hands. That makes a distributor's mailbox a great launch point for invoice fraud against everyone it does business with, whether or not files were ever encrypted.
The VPN note is the useful lesson for everyone else, whatever happened at Saber1. A firewall or VPN credential that leaked years ago can still work today if nobody reset it, patched the box, or added MFA. Plenty of lean industrial shops in Rome, Dalton, Chattanooga, and Birmingham run a similar setup: one firewall, one shared VPN account for the ERP consultant, and nobody checking whose passwords are already for sale.
Clear takeaway
Treat the Deadlock claim against Saber1 as a prompt to audit your own edge. Patch and lock down your firewall and VPN, reset any credentials that have shown up in leaks, and verify every payment change by phone. Don't assume a breach the company hasn't confirmed.
Actions to take this week
- Patch your firewall and VPN to the vendor's current supported firmware, and confirm the admin interface isn't reachable from the internet.
- Require MFA on VPN, email, ERP, and admin consoles. Retire shared VPN accounts and give each person and vendor their own login.
- Reset credentials that have leaked. Check your domain against breach and infostealer data, and rotate any VPN or admin passwords that predate your last firmware fix.
- Test an ERP and quote-file restore from a backup that ransomware can't alter or delete.
- Brief AP, sales, and key customers: new bank or remittance details get a call-back to a known number, never a reply to the email.
Brotherly Technology helps manufacturers, distributors, and industrial SMBs across Rome, Northwest Georgia, and the Southeast find the gaps a leak-site headline exposes, starting with the firewall, VPN, and backups. If you want a quick edge-and-identity review before the next claim lands, we're glad to help.
Sources:
- Ransomware.live: Saber1 / Deadlock. Discovered 2026-10-09 22:51 UTC; est. attack date 2026-10-09; credential-exposure and FortiBleed notes; claim-level only.
- ShellCodeX: Saber1, Deadlock claim. Listed Oct. 9, 2026; flagged as an unverified claim.
- Saber1 Technologies (saber1.com). Company context: machine-vision cameras, cables, lenses, frame grabbers, lighting; Lowell, MA. No incident acknowledgment cited here.