ASCII Group Data Breach

Alleged

Ransomware claim involving ASCII Group

Published: Aug 16, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ASCII Group
Industry
Technology
Threat Actor
Qilin
Date of Incident
Aug 16, 2026

Executive Summary

ASCII Group, a technology company based in Japan, has been identified as a victim of the qilin ransomware group. The listing on the group’s dark web portal was published on August 16, 2026, and detected by SOCRadar’s Dark Web Monitoring service. This incident places ASCII Group among an increasing number of entities targeted by qilin, highlighting the ransomware group’s persistent activity across various sectors and geographical locations. The company’s position within the technology sector may have made it an attractive target due to the potential value of its data and services. In the 60 days leading up to this listing, qilin claimed 186 other victims. The group has consistently targeted the Manufacturing, Professional Services, and Business Services sectors, with a primary focus on victims in the US, Germany, and France. Recent qilin victims, including INVENSITY, MOSAID Technologies, Avision, and Botek, demonstrate the group’s broad operational reach and diverse targeting strategies, which align with the profile of ASCII Group. This incident is consistent with qilin’s established pattern of targeting technology organizations.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for www.asciigroup.com revealed no matching records within the queried dataset. It is important to note that a null result does not conclusively indicate that the organization is unaffected. The query may have covered only a paginated or limited sample of available logs, and credentials could exist under alternate corporate domains or be associated with personal email aliases used by ASCII Group employees. Therefore, this absence of evidence should not be interpreted as definitive proof of no compromise. For ransomware groups like qilin, credentials harvested via infostealers serve as a documented vector for initial access. Threat actors or initial access brokers commonly source these credentials from underground marketplaces, validate them, and subsequently use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. The lack of observed records in this specific query does not preclude such a scenario, as credentials might have surfaced in datasets not covered by this analysis, been rotated prior to indexing, or been harvested using personal email aliases. Given these factors, CTI teams should continue monitoring dark web and stealer-log feeds for any related activity. Proactive measures such as credential hygiene checks, including password rotation and multi-factor authentication review, are recommended. Organizations should also monitor alternate corporate domains and review activity logs for Microsoft 365, VPNs, and remote-access portals to detect and mitigate potential intrusions.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.