Affinity Capital Data Breach

Alleged

Ransomware claim involving Affinity Capital

Published: Jul 30, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Affinity Capital
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Jul 30, 2026

Executive Summary

Qilin added Affinity Capital, a US financial services firm, to its leak site on July 30, 2026. SOCRadar’s Dark Web Monitoring flagged this listing. For a financial services company, the primary concern lies in the exposure of customer financial data and access to client portals, making customer liability a critical issue for the board, rather than solely focusing on IT remediation. Affinity Capital represents another U.S.-based entity in the high volume of activity attributed to the Qilin ransomware group. Qilin has been exceptionally active, claiming 122 other victims in the 60 days prior to this listing, positioning it as one of the most prolific operations tracked. The group’s recent targets have primarily been in the Business Services, Manufacturing, and Technology sectors, with a geographical focus on the United States, France, and Germany. The finance sector is frequently targeted, with previous victims including Triton Trading, EFU Life Assurance, Century Equities, and TQ Financial Services. Affinity Capital aligns with this pattern of targeting financial institutions and falls within the group’s predominant geographical focus on the U.S.

Technical Analysis

SOCRadar’s stealer-log correlation identified a potential exposure related to affinitycorp[.]net. Specifically, four records indicated external user authentications using consumer Gmail addresses, rather than corporate employee accounts, against an Affinity-owned login page at cisol.affinitycorp[.]net. This suggests that customer or third-party accounts on Affinity Capital’s portal may be exposed, which is categorized as a category-B intelligence signal, indicating potential portal security issues rather than compromised employee accounts. This finding does not definitively confirm that these exposed credentials were used for the ransomware incident but highlights a separate area of concern. The identified exposure points towards a need for a review of the portal’s account security and potential customer notification, rather than an internal password reset. It is crucial to analyze the portal’s authentication logs to assess the risk of account takeover for the affected users and to maintain ongoing monitoring. Qilin, in line with many ransomware operations, frequently utilizes infostealer logs for initial access. Threat actors or brokers purchase these logs to validate credentials and gain entry into portals or remote access systems before deploying ransomware. The observed customer-side exposure on a public-facing portal does not confirm that these specific credentials facilitated this incident, nor does it rule out their involvement. Organizations should review their portal authentication logs, assess account takeover risks for exposed users, and continue dark web and stealer-log monitoring.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.