Flex signed $3.3 billion of one-year debt eight days after a ransomware gang listed it

A ransomware gang listed Flex on 21 September, three days after three of the manufacturer's Okta logins surfaced in criminal stealer logs. Eight days later Flex signed $3.3 billion of one-year debt for its AI-power acquisition, and no filing mentions either record.

In this storyFLEXOKTA
Vincent JiangVincent Jiang · 3 min read
Share
Revathi Advaithi, chief executive officer of Flex
1 / 6Slide 1 of 6
Flex CEO Revathi Advaithi. Her company signed a $3.3 billion one-year term loan on 29 September 2026, eight days after the MetaEncryptor ransomware gang listed Flex on its leak site.

Three Okta logins, then a leak-site listing

On 18 September 2026, three employee logins for Flex's Okta identity service surfaced in criminal stealer logs, inside a batch of 21 credential records tied to flex.com that appeared between 18 and 21 September 1. Three days later the ransomware operation MetaEncryptor listed Flex, the Nasdaq-listed contract electronics manufacturer, on its leak site 12. SOCRadar, which surfaced the credentials, counted 20 victims for the group in the prior 60 days and called Flex its most substantial manufacturing claim in that run 1.

Eight days later, $3.3 billion of one-year paper

On 29 September, eight days after the listing, Flex signed the money leg of its AI-power pivot: a $3.3 billion senior term loan with Citibank as administrative agent, undrawn at signing and maturing 364 days after it funds, governed by a 4.50x Debt/EBITDA cap and a 3.00x interest-coverage floor 5. The Inference covered this financing on 4 October; what follows is the September record that story, and every filing behind it, leaves out.

The loan cuts dollar-for-dollar into a $4.4 billion bridge from Citigroup and Bank of America that backstops the all-cash purchase of EPC Power, a power-conversion maker expected to book about $800 million of 2026 revenue and bound for the unit Flex plans to spin off in the first quarter of 2027 345. In the quarter before signing, Flex's debt was up 39 percent year over year at $5.93 billion while free cash flow fell 85 percent to $41 million 11.

Debt hit $5.9B as free cash flow collapsed to $41M in Flex's June quarter

  • Total debt
  • Free cash flow
$0B$2B$4B$6BQ3 '24Q4 '24Q1 '25Q2 '25Q3 '25Q4 '25Q1 '26Q2 '26$5.93BEPC term loan signed weeks later,undrawn
Data
Total debtFree cash flow
Q3 '24$4.19B$0.22B
Q4 '24$4.15B$0.31B
Q1 '25$4.15B$0.33B
Q2 '25$4.26B$0.27B
Q3 '25$4.29B$0.31B
Q4 '25$5.02B$0.28B
Q1 '26$4.32B$0.21B
Q2 '26$5.93B$0.04B
Quarterly total debt and free cash flow, US$ billions; labels are calendar quarters, and Flex's fiscal year ends in March. Source: Sharadar quarterly fundamentals compiled from Flex's SEC filings, retrieved 4 October 2026.11

The filings investors read carry no line for it

Both 8-Ks read in full describe the financing and its risks across pages of spin-off caveats; neither contains the word ransomware, breach, or cybersecurity 35. Flex's EDGAR index shows no Item 1.05 cybersecurity incident report, the form a listed company files when an attack turns material 6. The loan coverage that followed recited the terms and stopped 78. The credit agreement prices Flex's leverage to two decimals; the public record prices its cyber risk at zero.

Twenty-one records, and a gang on its third name

The credential batch breaks down as three Okta logins, one for a Flextronics subsidiary innovation system, one for the corporate web admin panel, eight employee credentials reused on third-party SaaS platforms, and eight external users on that panel 1. Okta access matters because one login can unlock every connected cloud tenant, which is why SOCRadar tied the timing to the listing as a likely intrusion path, an inference it states as such 1.

Three of the 21 exposed records were Okta logins

  • Employee SaaS credentials838%
  • External panel users838.1%
  • Okta logins314.3%
  • Subsidiary innovation system14.8%
  • Corporate web admin panel14.8%
Data
SliceValueShare
Employee SaaS credentials838%
External panel users838.1%
Okta logins314.3%
Subsidiary innovation system14.8%
Corporate web admin panel14.8%
Composition of the 21 flex.com credential records that surfaced in criminal stealer logs between 18 and 21 September 2026. Source: SOCRadar Cyber Intelligence, 27 September 2026.1

The brand is not new: MetaEncryptor launched in 2022, stopped adding victims in July 2023, and researchers tied its leak-site template and its encryptor to the LostTrust rebrand before the name resurfaced 10. Four days before Flex, the same name claimed AECOM and 1.22 terabytes of data, unconfirmed, drawing a class-action probe within three days 9.

Why this might be nothing

Leak-site listings are extortion claims, not evidence. SOCRadar's own disclaimer concedes they cannot always be verified 1, and as of 4 October neither SOCRadar's alert nor the DailyDarkWeb post reports any published Flex data; both accounts trace to the single 21 September listing 12. Flex may have rotated the logins and moved on; if so, the filings were complete and the gap is only in the gang's marketing.

Where this resolves

The EPC closing, expected in the fourth quarter, and the Form 10 SpinCo has already filed under the name Axiom Solutions International will price the debt leg on their own 35. What would price the cyber hole is a data dump or countdown from MetaEncryptor, an Item 1.05 filing, or new risk language in the 10-Q that lands with October earnings; the full risk-factor rewrite waits for a 10-K around May 2027 6. Watch the leak site and the EDGAR index; one moves first.

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio