Quick Summary
AllegedExecutive Summary
Akira ransomware group listed DI.C.S.EL. S.R.L. on its dark web portal on September 22, 2026. DI.C.S.EL. is an Italian manufacturer that provides industrial and technical solutions to the Italian market. The listing was identified through SOCRadar’s Dark Web Monitoring service. Companies like DI.C.S.EL. often attract ransomware attacks due to their critical role in industrial supply chains and the potential for disruption if operations are halted. In the 60 days preceding this listing, Akira claimed 62 other victims, primarily in the United States, Germany, and the United Kingdom. The group’s targets are predominantly in the Manufacturing, Professional Services, and Other sectors. Notable recent victims include Coe Press Equipment and Anderson Industries, both in the US, as well as Manders and Pilot Precision. DI.C.S.EL. aligns with Akira’s established targeting profile, as the group frequently targets mid-sized European industrial manufacturers.
Technical Analysis
SOCRadar’s stealer-log query for the domain `dicsel[.]it` returned no records within the available dataset slice. It is important to note that this query is bounded and paginated, meaning that credentials may exist under alternate corporate domains or personal email aliases that were not captured in this specific search. Therefore, the absence of records in this particular query does not definitively rule out the compromise of credentials or systems. Given that the query for `dicsel[.]it` did not yield results, it does not confirm that the organization is unaffected by credential harvesting operations. Infostealer-malware is frequently used by ransomware groups to gather credentials from compromised systems. These stolen credentials can then be leveraged to gain initial access to corporate networks, validate access, or facilitate the deployment of ransomware. Consequently, continued dark web and stealer-log monitoring for DI.C.S.EL. S.R.L. is advisable. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for all corporate accounts, are also recommended. Monitoring of Microsoft 365, VPN, and other remote-access portal activity for suspicious logins or unauthorized access attempts should be maintained.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.