Flex signed $3.3 billion of one-year debt eight days after a ransomware gang listed it
A ransomware gang listed Flex on 21 September, three days after three of the manufacturer's Okta logins surfaced in criminal stealer logs. Eight days later Flex signed $3.3 billion of one-year debt for its AI-power acquisition, and no filing mentions either record.
Vincent Jiang · 3 min read
Three Okta logins, then a leak-site listing
On 18 September 2026, three employee logins for Flex's Okta identity service surfaced in criminal stealer logs, inside a batch of 21 credential records tied to flex.com that appeared between 18 and 21 September 1. Three days later the ransomware operation MetaEncryptor listed Flex, the Nasdaq-listed contract electronics manufacturer, on its leak site 12. SOCRadar, which surfaced the credentials, counted 20 victims for the group in the prior 60 days and called Flex its most substantial manufacturing claim in that run 1.
Eight days later, $3.3 billion of one-year paper
On 29 September, eight days after the listing, Flex signed the money leg of its AI-power pivot: a $3.3 billion senior term loan with Citibank as administrative agent, undrawn at signing and maturing 364 days after it funds, governed by a 4.50x Debt/EBITDA cap and a 3.00x interest-coverage floor 5. The Inference covered this financing on 4 October; what follows is the September record that story, and every filing behind it, leaves out.
The loan cuts dollar-for-dollar into a $4.4 billion bridge from Citigroup and Bank of America that backstops the all-cash purchase of EPC Power, a power-conversion maker expected to book about $800 million of 2026 revenue and bound for the unit Flex plans to spin off in the first quarter of 2027 345. In the quarter before signing, Flex's debt was up 39 percent year over year at $5.93 billion while free cash flow fell 85 percent to $41 million 11.
Debt hit $5.9B as free cash flow collapsed to $41M in Flex's June quarter
- Total debt
- Free cash flow
Data
| Total debt | Free cash flow | |
|---|---|---|
| Q3 '24 | $4.19B | $0.22B |
| Q4 '24 | $4.15B | $0.31B |
| Q1 '25 | $4.15B | $0.33B |
| Q2 '25 | $4.26B | $0.27B |
| Q3 '25 | $4.29B | $0.31B |
| Q4 '25 | $5.02B | $0.28B |
| Q1 '26 | $4.32B | $0.21B |
| Q2 '26 | $5.93B | $0.04B |
The filings investors read carry no line for it
Both 8-Ks read in full describe the financing and its risks across pages of spin-off caveats; neither contains the word ransomware, breach, or cybersecurity 35. Flex's EDGAR index shows no Item 1.05 cybersecurity incident report, the form a listed company files when an attack turns material 6. The loan coverage that followed recited the terms and stopped 78. The credit agreement prices Flex's leverage to two decimals; the public record prices its cyber risk at zero.
Twenty-one records, and a gang on its third name
The credential batch breaks down as three Okta logins, one for a Flextronics subsidiary innovation system, one for the corporate web admin panel, eight employee credentials reused on third-party SaaS platforms, and eight external users on that panel 1. Okta access matters because one login can unlock every connected cloud tenant, which is why SOCRadar tied the timing to the listing as a likely intrusion path, an inference it states as such 1.
Three of the 21 exposed records were Okta logins
- Employee SaaS credentials838%
- External panel users838.1%
- Okta logins314.3%
- Subsidiary innovation system14.8%
- Corporate web admin panel14.8%
Data
| Slice | Value | Share |
|---|---|---|
| Employee SaaS credentials | 8 | 38% |
| External panel users | 8 | 38.1% |
| Okta logins | 3 | 14.3% |
| Subsidiary innovation system | 1 | 4.8% |
| Corporate web admin panel | 1 | 4.8% |
The brand is not new: MetaEncryptor launched in 2022, stopped adding victims in July 2023, and researchers tied its leak-site template and its encryptor to the LostTrust rebrand before the name resurfaced 10. Four days before Flex, the same name claimed AECOM and 1.22 terabytes of data, unconfirmed, drawing a class-action probe within three days 9.
Why this might be nothing
Leak-site listings are extortion claims, not evidence. SOCRadar's own disclaimer concedes they cannot always be verified 1, and as of 4 October neither SOCRadar's alert nor the DailyDarkWeb post reports any published Flex data; both accounts trace to the single 21 September listing 12. Flex may have rotated the logins and moved on; if so, the filings were complete and the gap is only in the gang's marketing.
Where this resolves
The EPC closing, expected in the fourth quarter, and the Form 10 SpinCo has already filed under the name Axiom Solutions International will price the debt leg on their own 35. What would price the cyber hole is a data dump or countdown from MetaEncryptor, an Item 1.05 filing, or new risk language in the 10-Q that lands with October earnings; the full risk-factor rewrite waits for a 10-K around May 2027 6. Watch the leak site and the EDGAR index; one moves first.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.


