Quick Summary
AllegedExecutive Summary
Conway Analytics, a technology company based in the United States, was recently listed as a victim on the Everest ransomware group’s dark web portal. The listing, published on August 5, 2026, was identified by SOCRadar’s Dark Web Monitoring service. Operating within the technology and data analytics sector, Conway Analytics falls into a profile that aligns with the primary targeting patterns of the Everest ransomware group. The company’s industry and geographic location, the United States, are areas that Everest has consistently focused on in its recent operations, making it a susceptible target. In the 60 days preceding this listing, Everest had claimed 18 other victims, demonstrating significant activity. The group predominantly targets the technology, professional services, and energy and utilities sectors, with victims frequently located in the United States, India, and the United Arab Emirates. Conway Analytics’ situation is consistent with previous Everest campaigns, particularly the targeting of U.S. technology companies. Notable similar victims include Keysight, Formulatrix, Alzone Software, and Allied Telesis, placing Conway Analytics squarely within a cluster of recent, high-profile targets for the ransomware group.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for the domain conway.ai returned no records within the queried dataset. It is crucial to understand that a null result does not confirm the absence of a compromise. The query examined a paginated sample, not the entire data corpus, and may not encompass credentials associated with alternate or subsidiary corporate domains. Furthermore, credentials harvested using personal email aliases would not be correlated with the corporate domain. The indexing of newer generic top-level domains in stealer-log feeds is also less consistent than for legacy .com infrastructure, limiting the scope of a null verdict. For ransomware operations like those conducted by Everest, infostealer-harvested credentials are a well-established method for initial access. Threat actors or initial access brokers commonly source these credentials from underground marketplaces, validate them, and then use them to gain unauthorized access to systems, such as Microsoft 365, VPNs, or remote-access portals, before deploying ransomware. The lack of matching records in this specific query does not preclude this possibility; credentials could have appeared in other data feeds, been used and rotated before indexing, or been obtained under personal email addresses. Given the nature of ransomware operations and the limitations of the current telemetry, CTI teams should prioritize ongoing monitoring and proactive credential hygiene. This includes regular password rotation, review of multi-factor authentication configurations, and continued monitoring of alternate corporate domains and cloud access logs. Treating a null query as a definitive sign of security is inadvisable; instead, it underscores the importance of continuous vigilance and proactive security measures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.