Quick Summary
AllegedExecutive Summary
AYUDHYA TH Insurance, a financial services organization based in Thailand, has been identified as a victim by the DYSPHOR1A ransomware group. The listing, published on their dark web portal on August 20, 2026, was detected through SOCRadar’s Dark Web Monitoring service. Operating within Thailand’s insurance sector, AYUDHYA TH Insurance offers both life and general insurance products, utilizing the domain allianz.co.th. This incident positions the company within a pattern of DYSPHOR1A targeting Southeast Asian financial and institutional entities. In the 60 days leading up to this listing, DYSPHOR1A claimed six other victims. The group has consistently targeted the Education, Professional Services, and Government & Defense sectors, with a significant concentration of victims in Myanmar, Thailand, and Indonesia. Notable recent victims from the same Southeast Asian campaign include GUSTO College GLMS, Strategy First International College, Job Net .COM.MM, and the Indonesian Police Database. AYUDHYA TH Insurance marks a deviation from DYSPHOR1A’s typical sector focus, as it appears to be their first known target within the financial services industry.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the allianz.co.th domain in the period immediately preceding the DYSPHOR1A listing. Between August 12 and August 20, 2026, a total of 25 records were observed, all related to the organization’s eBiz online portal and insurance agency portal. The usernames primarily consisted of numeric or non-corporate formats, suggesting they belong to insurance agents and policyholders rather than internal employees. While this data points to exposure through external-facing portals rather than direct corporate workstation compromise, the access gained through the agency portal represents a critical risk surface for financial services organizations. For ransomware groups like DYSPHOR1A, credentials harvested by infostealers are a recognized method for initial access. Threat actors or initial access brokers typically acquire fresh logs from underground marketplaces, validate the credentials, and then use them to gain access to accessible portals before deploying ransomware. Although the observed stealer-log data does not definitively confirm the use of these specific credentials by DYSPHOR1A, the timing of the data harvesting—occurring in the eight days before the leak site listing—warrants thorough investigation. Threat intelligence teams should prioritize assessing whether any compromised agent portal accounts possessed elevated access to internal policy systems.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.