Quick Summary
AllegedExecutive Summary
TheGentlemen ransomware group listed Babcock, a South African defense engineering and support services company, on its leak site on August 19, 2026. SOCRadar’s Dark Web Monitoring identified this listing. The incident is notable due to stealer-log data that revealed 17 records associated with Babcock’s domain, babcock[.]co.za, with data freshness extending up to the publication date. This included customer-tier credentials targeting Babcock’s government client extranet, raising significant concerns about the potential exposure of sensitive government contract information. In the same publication window, four other victims were identified: Roadvision Systems (Sweden, Transportation), Senvest Capital (Canada, Financial Services), CRASL (UK), and Euroscreen (Italy, Technology). The varied industries and geographic locations of these victims suggest that the ransomware group’s targeting is likely driven by access availability rather than a specific sector-based campaign. This broad approach indicates a pragmatic strategy focused on exploiting any available vulnerabilities across diverse organizations.
Technical Analysis
SOCRadar’s investigation into Babcock involved querying stealer-log data for the domain babcock[.]co.za. The query returned 17 records, with data freshness extending up to the publication date of August 19, 2026. These records were categorized into 6 employee credentials, 7 customer-tier credentials, and 4 corporate credentials. The employee accounts appear to grant access to extranet.babcock[.]co.za, suggesting potential use for remote project collaboration or contractor access. The most concerning aspect of this exposure is the 7 customer-tier credentials. Given that Babcock’s defense extranet serves government clients, these credentials may belong to government agency personnel who use these portals for contract-related activities. The data freshness, unrotated until the listing date, indicates a potential window of opportunity for threat actors. This evidence does not confirm that these credentials were the specific entry point used by TheGentlemen, but it highlights a significant risk of unauthorized access to sensitive government contract information, including deliverables, procurement documentation, and project timelines. Immediate notification is recommended for both Babcock and any government clients whose personnel’s credentials may be compromised. Organizations should consider continued dark web monitoring for further listings, proactive credential hygiene checks, password rotation, multi-factor authentication review, and monitoring of alternate corporate domains, Microsoft 365, VPN, and remote-access activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.