DMT Consulting Private Limited Data Breach

Alleged

Ransomware claim involving DMT Consulting Private Limited

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
DMT Consulting Private Limited
Industry
Business Services
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

Krybit ransomware has claimed DMT Consulting Private Limited as a victim, with the listing appearing on September 1, 2026. SOCRadar’s Dark Web Monitoring identified this claim. DMT Consulting is a German-based engineering and technical consulting firm that provides specialized technology services across various sectors. The nature of its work, involving technology and consulting, makes it a potential target for ransomware and extortion activities due to the sensitive data it likely handles. In the 60 days preceding this listing, Krybit claimed 58 other victims. The group’s typical targeting focuses on Professional Services, Other, and Technology industries, with a geographic concentration in India, Thailand, and Brazil. Previous victims in the technology and consulting sectors include Arab Maritime Petroleum Transport Company, Syscon (Thailand) Co., Ltd., and Actini Group. DMT Consulting’s inclusion aligns with Krybit’s established targeting patterns within the technology and business services sectors.

Technical Analysis

A query for stealer-log records associated with the domain dmt-group[.]com revealed 26 records spanning from June 2024 to August 2026. Of these, 16 were identified as employee credentials. The queried endpoints include Autodesk (a design and collaboration platform common in engineering), pims.dmt-group[.]com (an internal project management system), and testdust.dmt-group[.]com (a test/staging environment). This extensive credential exposure over a 14-month period, without evidence of rotation, presents a significant corporate intrusion risk. The presence of multiple distinct corporate usernames appearing repeatedly across Autodesk and internal systems over this 14-month window, without any indication of credential rotation between June 2024 and August 2026, suggests a prolonged period of potential unauthorized access. For an engineering consultancy, access to platforms like Autodesk implies access to sensitive design files, client project data, and collaboration records. This prolonged credential exposure window is sufficient for extensive data exfiltration prior to the ransomware listing. The immediate recommendation is to rotate all Autodesk and PIMS credentials without delay. Furthermore, a thorough review of access logs from June 2024 onward is advised, with a specific focus on any unusual bulk file download or export activity. Continued monitoring of dark web and stealer-log feeds for the dmt-group[.]com domain and associated entities is also recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.