Affinity Capital Data Breach

Alleged

Ransomware claim involving Affinity Capital.

Published: Jul 30, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Affinity Capital
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Jul 30, 2026

Executive Summary

Affinity Capital, a financial services company based in the United States, was recently identified as a victim on the Qilin ransomware group’s dark web portal, with the listing published on July 30, 2026. This information was surfaced by SOCRadar’s Dark Web Monitoring service. Operating within the financial services sector, Affinity Capital is particularly susceptible to data breaches due to the sensitivity of customer financial data and associated portal access. The company’s inclusion in this listing is part of a broader pattern of recent, high-volume activity by the Qilin group targeting U.S.-based organizations. Over the 60 days preceding this listing, Qilin declared 122 other victims on its leak portal, positioning itself as one of the most active ransomware operations currently in operation. The group consistently targets the Business Services, Manufacturing, and Technology sectors, with a significant concentration of victims located in the United States, followed by France and Germany. Affinity Capital’s profile aligns with previous targets in the financial services sector, including Triton Trading, EFU Life Assurance, Century Equities, and TQ Financial Services. Its targeting reflects Qilin’s ongoing focus on the finance industry and its preference for attacking entities within the United States.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a potential credential exposure associated with the affinitycorp.net domain. Specifically, four records indicated external-user credentials, utilizing consumer Gmail addresses instead of corporate accounts, authenticating against an organization-owned authentication subdomain (cisol.affinitycorp.net). This finding is classified as a category-B signal, suggesting customer or third-party account exposure on Affinity Capital’s portal. It does not definitively confirm a direct compromise of internal employees, but it does highlight a vulnerability associated with the company’s own portal’s login endpoint. Given the nature of the exposed accounts and the login endpoint, a thorough review of the portal’s account security and customer notification procedures is recommended. For ransomware groups like Qilin, compromised credentials obtained from infostealer logs are a known method for initial access. Threat actors or their brokers acquire these logs from underground marketplaces, validate the credentials, and then use them to access portals, VPNs, or remote-access systems before deploying ransomware. The detected stealer-log evidence points to exposure of external-user credentials on a customer-facing portal. This data alone does not confirm that these credentials were the initial access vector for the incident; their involvement cannot be definitively inferred. CTI teams should therefore review authentication logs for the affected portal, assess the risk of account takeover for the exposed users, and maintain ongoing monitoring. It is crucial to understand that the presence or absence of such telemetry does not serve as conclusive evidence of a compromise. Recommended actions include continued dark web and stealer-log monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review for affected systems.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.