Euroscreen Data Breach

Alleged

Ransomware claim involving Euroscreen.

Published: Aug 19, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Euroscreen
Industry
Technology
Threat Actor
TheGentlemen
Date of Incident
Aug 19, 2026

Executive Summary

The ransomware group TheGentlemen listed Euroscreen, an Italian company specializing in display and visualization technology, on their leak site on August 19, 2026. This incident falls within a pattern of activity where TheGentlemen targets companies across various sectors. SOCRadar’s Dark Web Monitoring service identified this listing, bringing attention to the potential compromise of Euroscreen’s data. The timing of the listing and the inclusion of Euroscreen in a batch with other international companies suggests a coordinated effort by the threat actor. TheGentlemen has been active recently, and this listing of Euroscreen aligns with their broader targeting trends, which often include companies in industries such as manufacturing, telecommunications, business services, education, finance, healthcare, technology, retail, government, and transportation and logistics. The group’s typical victims are located in various countries, and the inclusion of Euroscreen, alongside victims from South Africa, Sweden, Canada, and the UK, highlights the group’s global reach and diverse targeting strategy. This incident does not appear to deviate significantly from the group’s established modus operandi.

Technical Analysis

SOCRadar’s analysis of the domain euroscreen[.]it identified 25 stealer-log records. Of these, 10 are classified as customer-tier credentials, while the remaining 15 have an affiliation that is currently unclear. All these records authenticate against the euroscreen[.]it web platform. A recurring path component, “/infinity/cms,” suggests that these credentials are being used to access a Content Management System (CMS) portal. The timestamps of these records range from July 20 to August 19, 2026, indicating that the credentials were live and potentially in use up to and including the day the listing was discovered. The primary exposure identified is customer account takeovers (ATO). However, there is a secondary risk: if any of the 25 identified credentials are associated with CMS administrative accounts, this could grant the threat actor backend access to Euroscreen’s systems. Given that Euroscreen operates within Italy, the potential compromise of customer data also necessitates an assessment of GDPR notification obligations. Audit the access controls for the “/infinity/cms” path. Ascertain whether any of the harvested credentials possess administrative privileges. Initiate a forced rotation of all 25 identified credentials. Evaluate the regulatory requirements for GDPR notifications based on the scope of compromised customer data.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.