Quick Summary
AllegedExecutive Summary
Dunagan Associates, a business services company located in the United States, has been identified as a victim on the Genesis ransomware group’s dark web portal. The incident was published on July 5, 2026, and detected by SOCRadar’s Dark Web Monitoring service. The company operates within the business services sector, aligning with a common targeting pattern observed for the Genesis ransomware group, which frequently victimizes small and mid-sized US service firms.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry did not yield direct evidence of initial access for dunaganassociates.com within the queried data. However, the absence of immediate findings does not confirm the company’s security. Credentials from infostealer logs are a known initial access vector for Genesis, where threat actors source and utilize compromised credentials to gain entry to corporate networks via services like Microsoft 365 or VPNs. It is possible that credentials were harvested through personal email aliases, used and rotated before indexing, or accessed via feeds not included in the analyzed dataset. Therefore, continued monitoring and proactive credential hygiene are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.