Quick Summary
AllegedExecutive Summary
LockBit 5 ransomware group listed DeCe COMPUTERS s.r.o. as a victim on its leak site on August 27, 2026. DeCe COMPUTERS s.r.o. is a technology company based in the Czech Republic, operating within the IT hardware and software services sector. This targeting of a technology company aligns with LockBit’s historical patterns, as such entities often possess valuable data or critical infrastructure that can be leveraged for extortion. The listing was identified through SOCRadar’s Dark Web Monitoring. In the 60 days preceding this listing, LockBit 5 claimed responsibility for attacks against 32 other entities. The group’s primary targets are typically within the technology, professional services, and manufacturing sectors. Geographically, Germany, the United States, and France have been the most frequently targeted countries. The group has recently targeted other technology sector companies such as takt, TECOSIM, and SIRSA, indicating a consistent focus on this industry. DeCe COMPUTERS s.r.o.’s inclusion fits within this established pattern of targeting technology firms.
Technical Analysis
SOCRadar’s investigation identified severe stealer-log exposure on the domain `dece[.]cz`. Specifically, two records were found: an employee credential associated with `mail[.]dece[.]cz`, which appears to be a corporate mail server, and another record for an address using the `@dece[.]cz` domain on a third-party service. These records date from February to May 2026 and indicate that the credentials were not rotated at the time of indexing. This pattern is consistent with workstation compromise, where an infected endpoint harvests credentials as the user accesses various external platforms. The presence of corporate email credentials and exposure on third-party services is a recognized precursor to ransomware attacks. While this telemetry does not confirm that LockBit 5 specifically accessed DeCe COMPUTERS s.r.o.’s systems using these credentials, the exposure warrants immediate action. The unrotated nature of these credentials during the February–May 2026 window highlights a significant risk. The observed stealer-log exposure, particularly the corporate email credential, serves as a significant indicator of potential compromise. This type of information can be valuable for threat actors seeking to gain initial access or escalate privileges within a network. It is crucial for organizations to proactively monitor for such exposures and implement robust credential hygiene practices to mitigate these risks. The identified exposure window suggests that an in-depth review of remote access logs during that period would be advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.