Quick Summary
AllegedExecutive Summary
Bihl, a Germany-based organization operating under the domain bih[.]com[.]sg, was identified on Akira’s leak site on August 24, 2026. The presence of a .sg domain, despite the company’s German classification, suggests potential cross-jurisdictional operations. Akira has a well-established pattern of targeting European entities, and German organizations have frequently appeared on the ransomware group’s victim list across various sectors, indicating a consistent focus on this region and industry profile. In the 60 days preceding this listing, Akira claimed 40 victims. The ransomware group’s most frequently targeted sectors include Business Services, Manufacturing, and Retail & E-Commerce, with the United States, the UK, and Canada being their primary geographic focus. Akira demonstrates a broad global reach, not typically constraining its victim selection by specific geography or industry. Notable recent victims attributed to Akira include Franz Krause artworksgroup, JC Sales, Deas Millwork, and Cascade Coffee, underscoring the group’s ongoing activity and wide-ranging impact.
Technical Analysis
SOCRadar’s investigation utilizing stealer-log telemetry did not return any records associated with the domain bih[.]com[.]sg within the queried dataset. However, Bihl’s international operational structure, with German operations linked to a .sg domain, presents a complex credential exposure landscape. It is plausible that relevant credentials may exist under different, unqueried domain search terms, particularly those associated with Singaporean affiliations. Therefore, a null result from this specific query is not sufficient to conclude that credential exposure is absent. Akira’s operational methodology involves sourcing infostealer logs from underground marketplaces to obtain corporate credentials. These credentials are then validated and used to authenticate against systems such as Microsoft 365, VPNs, or other remote-access portals before ransomware deployment. For Bihl, the use of a .sg top-level domain for what appears to be a German-operated entity highlights a potentially extensive credential surface. Consequently, stealer-log queries limited solely to the primary domain may not capture the complete scope of potential exposure. Given this scenario, it is advisable for Bihl to expand their threat intelligence monitoring to include any Singapore-registered or affiliated domains. This broader search scope is crucial for a more comprehensive understanding of potential credential exposure. Continued dark web monitoring and proactive credential hygiene checks, including password rotation and multi-factor authentication review, are also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.