Diarco Data Breach

Alleged

Ransomware claim involving Diarco

Published: Sep 17, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Diarco
Industry
E-Commerce
Threat Actor
INC Ransom
Date of Incident
Sep 17, 2026

Executive Summary

Diarco, an Argentine company operating in the wholesale distribution and retail sectors, has been identified as a claimed victim of the INC Ransom ransomware group. The listing appeared on the group’s dark web portal on September 17, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. Companies in the retail and e-commerce industries are frequently targeted by ransomware operations due to the potential for significant financial disruption and the sensitive customer data they possess. In the 60 days leading up to this listing, INC Ransom claimed 64 victims, positioning them as a highly active threat actor. Their typical targets include the Manufacturing, Professional Services, and Healthcare industries, with a strong geographic focus on the United States, Canada, and Malaysia. Diarco’s listing represents a geographical expansion for INC Ransom, as it is based in Argentina, a region less commonly targeted by the group compared to predominantly English-speaking countries. Other organizations previously listed by INC Ransom include Oleoductos del Valle, Appliance Factory & Mattress Kingdom, jms building corporation, and Cullotta Bravo Law Group, highlighting a pattern of targeting businesses across various sectors.

Technical Analysis

SOCRadar’s telemetry detected a severe credential exposure linked to the diarco[.]com[.]ar domain. Analysis of a sample of 25 records revealed nine employee credentials associated with organizational systems, including multiple usernames ending in @diarco.com.ar. The exposure also included high-value endpoints such as login.microsoftonline[.]com (used for Microsoft 365 identity), diarco-hr01.diarco[.]com[.]ar (an internal HR and administrative system), and an Invgate ITSM tenant. Notably, the data showed a recurring credential pattern on a domain mimicking Microsoft Online, suggesting potential credential interception through phishing infrastructure or endpoint malware. Additional records included two corporate users on third-party services and six customer/external records. The presence of these credentials, particularly those tied to Microsoft 365 identity and internal HR systems, coupled with evidence of long-tail persistence and potential interception via a typosquat domain, elevates this exposure to a high-priority remediation concern. INC Ransom operators are known to validate stolen credentials against platforms like Microsoft 365, VPNs, and internal portals before deploying ransomware. The identified exposure directly aligns with their operational tactics, indicating a significant risk of unauthorized access and subsequent ransomware deployment against Diarco. The urgency of addressing this credential exposure cannot be overstated. Recommended immediate actions include rotating credentials across Microsoft 365 and Invgate accounts. Furthermore, a thorough review of access logs for the HR system is crucial to detect any unauthorized activity. Continued monitoring of the dark web and stealer-log feeds for any further related exposures is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.