Advanced Engineering Consultants Data Breach

Alleged

Ransomware claim involving Advanced Engineering Consultants.

Published: Aug 19, 2026 coinbasecartel
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Advanced Engineering Consultants
Industry
Business Services
Threat Actor
coinbasecartel
Date of Incident
Aug 19, 2026

Executive Summary

Advanced Engineering Consultants (AEC) was listed as a victim on the dark web leak site of the Coinbase Cartel ransomware group on August 19, 2026. This listing coincided with the threat actor also claiming victimhood for Crowe, a prominent US accounting firm, suggesting a potential targeted sweep of professional services organizations. AEC, which offers civil, structural, and MEP engineering consulting services, was identified through SOCRadar’s Dark Web Monitoring service. The timing and simultaneous listing of two significant professional services entities imply a strategic approach by Coinbase Cartel, possibly indicating either a curated target list or bulk access acquisition from a specialized broker within the sector. Coinbase Cartel has been actively targeting organizations within the professional services and technology sectors. Their operational focus in the 60 days preceding this incident was particularly on advisory and consulting firms, aligning with the inclusion of AEC and Crowe. This pattern suggests a deliberate strategy to exploit organizations that handle sensitive client data and intellectual property. The group’s recent activity indicates a consistent targeting of industries that are critical to business operations and financial transactions, making them high-value targets for extortion.

Technical Analysis

SOCRadar’s infostealer telemetry data revealed a concerning finding for Advanced Engineering Consultants, with 17 records associated with the domain aec.com, categorized as severe. This data included 11 employee credentials on organizational systems, 2 customer records, and 4 corporate credential entries. The identified employee credentials provided access to critical internal systems such as Microsoft Exchange OWA (mail.aec.com), an internal HR portal, the corporate domain aec.com, and Telegram. The exposure of credentials for Microsoft Exchange OWA is particularly significant, as it grants an attacker comprehensive visibility into email and calendar data, which can be leveraged for targeted phishing campaigns or the exfiltration of sensitive project information. The inclusion of Telegram access might indicate its use as a secondary communication channel by employees, potentially holding further valuable information. These records span multiple geographic locations and range from July 1 to August 10, 2026, a period ending just nine days prior to the Coinbase Cartel leak site listing. While the retrieved stealer-log data does not definitively confirm that Coinbase Cartel utilized these specific credentials for an intrusion, the presence of 11 employee identities with access to sensitive systems like OWA and the HR portal, surfacing shortly before the leak site claim, is highly indicative of the reconnaissance phase that often precedes ransomware deployment. The identified Microsoft Exchange environment and associated employee accounts represent crucial areas for immediate investigation and enhanced security monitoring.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.