Quick Summary
AllegedExecutive Summary
Qilin ransomware listed Alicotrans, a Brazilian freight and logistics company, on its leak portal on September 14, 2026. This listing occurred approximately two months after evidence of credential exposure for Alicotrans employees was documented between June and July 2026. SOCRadar’s Dark Web Monitoring identified this claim. The timing of the leak suggests a typical ransomware operation timeline, where credential exposure precedes data exfiltration and public shaming. Alicotrans’ operations within the transportation sector may have made it a target, as this industry is frequently targeted by ransomware groups. Qilin has been identified as one of the most active ransomware operations, claiming 242 victims in the 60 days preceding Alicotrans’ listing. The group’s primary targeted industries include Transportation, Manufacturing, and Professional Services. While Qilin predominantly targets organizations in the United States, Germany, and the United Kingdom, Alicotrans represents another South American transportation victim, aligning with the group’s sectoral focus. This incident follows other Qilin claims, such as Philippine Ports Authority, Globalport Terminals, Tramigo, and California Truck Equipment, within the same observation window.
Technical Analysis
SOCRadar’s analysis of stealer-log data for alicotrans[.]com yielded two relevant records from June to July 2026. One record indicated credentials logged directly against the victim’s own domain, suggesting potential direct organizational access. The second record involved a corporate email address used on a third-party service, which is consistent with credential harvesting from workstation compromise across multiple browsing sessions. This indicates a mixed profile of potential access, encompassing both workstation-level compromises and direct organizational access signals. The observed timeline of credential exposure in June-July 2026, followed by the ransomware group’s listing in September 2026, aligns with common ransomware operational patterns. This two-month gap typically allows ransomware actors sufficient time for credential validation, potential sale through access brokers, and preparation for data exfiltration and system encryption. The nature of the exposure points to a scenario where compromised credentials could facilitate unauthorized access, potentially leading to the ransomware attack. It is recommended that Alicotrans review its authentication logs for any direct access to its infrastructure between June and September 2026. Particular attention should be paid to the credential associated with the primary domain record found in the stealer logs. Further monitoring of dark web and stealer-log feeds for any additional compromise indicators is also advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.