Downies Collectables Pty Ltd Data Breach

Alleged

Ransomware claim involving Downies Collectables Pty Ltd

Published: Jul 21, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Downies Collectables Pty Ltd
Industry
Consumer Services
Threat Actor
Settra
Date of Incident
Jul 21, 2026

Executive Summary

On July 21, 2026, the ransomware group Settra claimed Downies Collectables Pty Ltd as a victim on its leak site. Downies Collectables Pty Ltd is an Australian consumer services company that operates a significant e-commerce and auctions business. SOCRadar’s Dark Web Monitoring flagged this listing. Alongside the leak-site claim, analysis of stealer-log data revealed associated exposure concerning Downies’ customers. Given the nature of its business, which involves customer transactions and potentially sensitive personal information, Downies Collectables Pty Ltd represents a profile that could attract ransomware and extortion activity. In the preceding 60 days before this listing, Settra had claimed approximately 20 other victims. These victims were primarily within the business services, consumer services, and technology sectors. The group’s preferred geographic targets include the United States, the United Kingdom, and Germany. Recent victims attributed to Settra include VCNY Home, LifeVantage Corporation, Torsion Group, and WT Law LLP. While Downies Collectables Pty Ltd is located in Australia, placing it outside Settra’s typical geographic focus, the company’s consumer-facing profile aligns well with the group’s common targeting patterns.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry indicated a notable credential exposure related to the domain downies[.]com. The query examined a specific dataset and returned approximately two dozen credentials. These credentials were primarily associated with the main domain and its auctions subdomain. Importantly, the vast majority of these exposed credentials belonged to external users, including those using consumer email providers and generic handles targeting a customer login endpoint, rather than internal employee accounts. The recurrence of several usernames across different dates suggests either the practice of credential reuse by users or persistent harvesting targeting the same customer accounts over time. The observed data spanned from late June to mid-July 2026, with a trailing pattern of fresh exposures. The findings from the stealer-log telemetry do not directly confirm a Settra initial access path to Downies Collectables Pty Ltd’s corporate network, nor did the sample surface any employee or administrative credentials. However, the substantial volume and persistence of exposed customer logins represent a significant account takeover risk for customers. This issue operates in parallel to the leak-site listing by Settra. It is possible that corporate credentials might still exist outside the scope of this specific data sample. Therefore, organizations should prioritize customer notification regarding the exposed credentials and implement multi-factor authentication for customer-facing portals. Continued monitoring for any further corporate credential exposure is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.