Air International Thermal Systems Data Breach

Alleged

Qilin ransomware claim involving Air International Thermal Systems

Published: Aug 26, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Air International Thermal Systems
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Aug 26, 2026

Executive Summary

Air International Thermal Systems, a UK-based manufacturer specializing in thermal management and HVAC systems for the automotive and transportation sectors, has been listed as a victim by the Qilin ransomware group. The claim was posted on Qilin’s dark web portal on August 26, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. While the listing is considered an allegation, it has not been independently confirmed. The company’s position within the manufacturing industry, particularly its role in supplying critical components for automotive and transportation, could make it an attractive target for cybercriminals seeking to disrupt supply chains or extort significant ransoms. The Qilin ransomware group has demonstrated significant activity, claiming 217 victims in the 60 days preceding this listing. Their primary targets have historically been the Manufacturing, Professional Services, and Technology sectors, with a notable geographic concentration in the United States, Germany, and Italy. Air International Thermal Systems aligns with a specific pattern observed in Qilin’s recent operations: a repeated targeting of UK-based manufacturing companies. This is further evidenced by previous claims against Filtronic (UK, Manufacturing), Dynamic Laser Solutions Ltd. (UK, Manufacturing), SC PaderTeG Cabluri Electrice (Romania, Manufacturing), and Black Cat Engineering & Construction WLL (Qatar, Manufacturing), indicating a potential focus on industrial supply chains.

Technical Analysis

SOCRadar’s stealer-log telemetry analysis for the domain ai-thermal[.]com yielded 13 records, detailing 8 unique corporate usernames associated with the @ai-thermal.com email domain. Crucially, all identified records place corporate credentials on third-party Software-as-a-Service (SaaS) infrastructure, rather than on internal identity or email systems. This suggests that compromised credentials may originate from external platforms used by the organization. The exposure window for these credentials spans an eight-month period, from December 2025 through August 2026. The telemetry data reveals specific patterns of credential exposure across several platforms. For app.asana.com, five records were found between February and July 2026, featuring a recurring masked user and varying passwords, which could indicate unrotated credentials or repeated endpoint reinfections. A single masked corporate user from Ninox (a database and collaboration tool) was identified, accessed via web and Android clients between March and May 2026. Additionally, two records were found for app.bom[.]com, a bill-of-materials/supply-chain platform, involving a distinct @ai-thermal.com user and dated February through March 2026. The overall profile suggests a risk of workstation compromise. The extensive history of credential exposure across multiple employee endpoints over an eight-month period is a significant concern, pointing either to persistent adversary access or repeated reinfection events following failed remediation efforts. The exposure on the bom[.]com platform is particularly relevant given Air International Thermal Systems’ manufacturing sector, potentially offering insights into supply chain vulnerabilities. While these findings do not definitively confirm the specific entry vector used by Qilin, they are consistent with the credential-sourcing kill chain commonly employed by the group and its associated initial access brokers. It is recommended that Air International Thermal Systems rotate credentials and enforce Multi-Factor Authentication (MFA) for all identified @ai-thermal.com accounts, prioritizing the Asana account due to its prolonged and recurring exposure.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.