Capgemini Engineering Data Breach

Alleged

Ransomware claim involving Capgemini Engineering

Published: Aug 20, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Capgemini Engineering
Industry
Aerospace
Threat Actor
Everest
Date of Incident
Aug 20, 2026

Executive Summary

Capgemini Engineering, a prominent global technology and professional services organization headquartered in France, has been listed as a victim on the dark web portal of the Everest ransomware group. This listing was identified on August 20, 2026, through SOCRadar’s Dark Web Monitoring service. As a significant provider of engineering and R&D services to a diverse client base across sectors such as aerospace, automotive, defense, energy, and digital infrastructure worldwide, Capgemini Engineering represents a high-value target for cybercriminals. Its position as one of Europe’s leading technology services firms makes this listing particularly noteworthy within Everest’s claimed victim portfolio. In the 60 days preceding this listing, Everest has claimed a substantial 25 other victims, indicating a period of high operational activity and a prolific threat actor. The group exhibits a broad industry focus, with a notable concentration on Professional Services, Technology, and Financial Services, and has targeted organizations across France, Spain, and the United States, among other locations. Recent victims with similar profiles include Experts Entreprendre, Aptara, Oasis Legal Group, and Grupo DT. Capgemini Engineering’s extensive global operations and its role as a custodian of client data align with the typical profile of organizations targeted by a group operating at Everest’s demonstrated pace.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure related to the capgemini.com domain. The query returned 11 credentials classified as INTERNAL_AUTH_EMPLOYEE, all directed at sign-in and Security Token Service (STS) infrastructure. These endpoints are critical for Capgemini’s identity federation and Single Sign-On (SSO) capabilities. Notably, all recovered records have log and insert dates of August 20, 2026, coinciding with the date of the ransomware group’s listing. The compromise of STS and sign-in infrastructure is particularly concerning for enterprise environments, as STS tokens can be leveraged to gain access to cloud services, VPNs, and internal applications without necessitating traditional password authentication, thus potentially bypassing standard security alerts. For ransomware operations, credentials harvested by infostealers represent a well-established initial access vector. Threat actors or initial access brokers often source fresh logs from underground marketplaces, validate the stolen corporate credentials, and then use them to access critical systems such as Microsoft 365, VPNs, or identity federation services. This access is a precursor to deploying ransomware or conducting data exfiltration. While the recovered stealer-log data does not definitively confirm that these specific credentials were used by the Everest group for an intrusion, the presence of 11 employee credentials targeting identity-critical infrastructure on the same day as the leak-site listing presents a strong temporal correlation. This suggests a potential pre-breach scenario, making it imperative for Capgemini’s security team to take immediate action. The security team at Capgemini should prioritize the revocation of affected SSO sessions, conduct a thorough review of STS audit logs, and implement forced credential rotation for all compromised accounts. Continued monitoring of dark web marketplaces and stealer-log feeds for any further exposure related to Capgemini’s domains and infrastructure is also recommended. Proactive credential hygiene checks, including reviewing and strengthening multi-factor authentication policies and monitoring for anomalous activity on Microsoft 365, VPNs, and remote access portals, are crucial steps to mitigate potential further compromise.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.