Eana Data Breach

Alleged

Ransomware claim involving Eana

Published: Jul 19, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Eana
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Jul 19, 2026

Executive Summary

Eana, an organization based in Argentina, has been listed as a victim on the Qilin ransomware group’s dark web leak portal, with the entry published on July 19, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The entry places Eana among the most recent additions to Qilin’s victim population, suggesting this incident may be part of the group’s ongoing operations. In the 60 days preceding this listing, Qilin claimed 126 other victims. The group has shown a preference for the business services, manufacturing, and consumer services sectors, with a geographical concentration of victims in the United States, Australia, and Germany. Other recent victims listed by Qilin that share similarities with Eana include Cafar, Metal Sur Famin, Associated Theatrical Contractors, and Don Tortaco Mexican Grill. Eana’s inclusion appears to fit within this broader pattern of opportunistic targeting rather than indicating a change in the group’s typical modus operandi.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry indicated a significant exposure for the eana.com.ar domain. The queried sample revealed 10 records linked to employee credentials for organizational systems, 3 records showing corporate users accessing third-party services, and 10 records associated with customer, supplier, or external accounts on the organization’s systems. Key high-value endpoints identified include the organization’s Microsoft 365/Entra ID single sign-on and an internal self-management portal. The observed credentials spanned from July 13 to July 18, 2026, indicating a fresh set of potentially compromised access information. For ransomware groups like Qilin, credentials harvested by infostealers are a well-recognized vector for initial access. Operators or initial-access brokers typically acquire recent logs from underground marketplaces, validate the corporate credentials, and use them to gain access to platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this discovery of stealer-log data does not definitively confirm that these specific credentials were used by Qilin, the observed pattern aligns with the typical kill chain for such incidents. Given the exposure of these credentials and their proximity to the Qilin listing, CTI teams should prioritize immediate credential rotation for all identified accounts. Enforcement of multi-factor authentication and a thorough review of endpoint activity are crucial. The exposed accounts should be treated as a live risk that could facilitate further intrusion rather than a historical artifact. Continued monitoring of dark web marketplaces and stealer-log feeds for any further activity related to Eana is also recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.