DICON Data Breach

Alleged

Ransomware claim involving DICON.

Published: Jul 5, 2026 Genesis
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
DICON
Industry
Business Services
Threat Actor
Genesis
Date of Incident
Jul 5, 2026

Executive Summary

DICON, an organization located in the United States, was identified as a victim of the Genesis ransomware group. The listing appeared on the Genesis group’s dark web portal on July 5, 2026, as detected by SOCRadar’s Dark Web Monitoring service. While DICON’s specific industry sector is not detailed in the monitoring data, its US location aligns with Genesis’s primary targeting patterns. The company’s listing is part of a larger trend of US-based entities targeted by the group in early July. Genesis ransomware has been active in the past 60 days, claiming multiple victims. The group tends to focus on the business services, healthcare, and technology sectors, with a strong geographical preference for the United States, though occasional targets in Jamaica and Canada have been noted. DICON’s case, along with other recent US listings, suggests a broad US-centric targeting approach rather than a niche industry focus.

Technical Analysis

Analysis of SOCRadar’s stealer-log telemetry revealed limited exposure for the dicon.com domain. A single record was found associating a corporate email address with a third-party catalog website. This pattern suggests that credentials may have been harvested from a stealer-infected employee workstation, rather than a direct compromise of DICON’s internal systems. The evidence points to a workstation compromise risk, with the observed log activity dating back to December 2025. No high-value internal endpoints such as identity providers, mail servers, or VPNs were present in the analyzed data. Credentials obtained via infostealers are a known initial access vector for ransomware groups like Genesis. Threat actors often source fresh logs from marketplaces, validate corporate credentials, and use them to gain access to systems like Microsoft 365, VPNs, or remote access portals to deploy ransomware. While the stealer-log data does not confirm Genesis’s use of this specific credential, exposed corporate accounts from compromised endpoints are a typical entry point for such attacks. CTI teams are advised to prioritize identifying and isolating affected endpoints, rotating exposed credentials, and searching for additional logs linked to the domain.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.