Customs Watch Data Breach

Alleged

Ransomware claim involving Customs Watch.

Published: Jul 16, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Customs Watch
Industry
Public Sector
Threat Actor
The Gentlemen
Date of Incident
Jul 16, 2026

Executive Summary

Customs Watch, a public sector organization based in the United States, was identified on July 16, 2026, as a victim on the dark web portal of the ransomware group The Gentlemen. This discovery was made through SOCRadar’s Dark Web Monitoring service. The listing places Customs Watch within The Gentlemen’s recent pattern of cyber activity, which has impacted various sectors and regions. The nature of public sector organizations, handling sensitive data and operating critical infrastructure, can make them attractive targets for ransomware groups seeking financial gain or disruption. In the 60 days leading up to this listing, The Gentlemen has claimed responsibility for at least 132 other victims. The group has historically shown a preference for targeting the Business Services, Manufacturing, and Healthcare sectors. Geographically, its most frequent targets are organizations located in the United States, Germany, and France. Recent victims with profiles similar to Customs Watch include Landesbibliothek Coburg, CSIR Structural Engineering Research Centre, Virginia Historical Society, and Terry P Moosmann CPA PC. Customs Watch’s placement within the Public Sector in the United States aligns with the group’s established targeting tendencies.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry identified a significant exposure related to the customswatch.com domain. The scan yielded 11 records, including credentials for five employee accounts on organization-owned systems, two customer or partner accounts, and three corporate user accounts associated with third-party services. Notable compromised endpoints identified through these credentials include corporate Google Workspace logins, a cPanel/webmail login on the organization’s own mail infrastructure, and a cloud file-sharing service. A singular corporate account was found to be duplicated across both internal and external contexts, strongly indicating a pervasive risk of corporate intrusion. The timeframe for these exposures is extensive, ranging from November 2025 to mid-July 2026, with evidence of repeated password reuse suggesting that credentials on a compromised endpoint may not have been rotated. For ransomware actors like The Gentlemen, the harvesting of credentials through infostealers represents a well-established pathway for initial access. Threat actors or initial access brokers frequently acquire recent logs from underground marketplaces. They then validate the corporate credentials found within these logs to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately to deploy ransomware. While the stealer-log data presented here does not definitively confirm that these specific credentials were utilized by The Gentlemen for the Customs Watch listing, the identified pattern is highly consistent with the typical intrusion kill chain observed for this category of cyber incident. Consequently, the compromised accounts and associated endpoints should be considered high-priority targets for immediate credential rotation and thorough security review.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.