Quick Summary
AllegedExecutive Summary
Qilin listed Excel Consultores, a Mexican professional services firm, on its leak site on July 30, 2026. SOCRadar’s Dark Web Monitoring service identified the listing. Mexico is an unusual location for Qilin, as its recent victims have predominantly been in the U.S., France, and Germany, making this one of the few Latin American entities claimed by the group. For a professional services firm, the data it holds, including client information and compliance systems, significantly raises the stakes in the event of a compromise. In the 60 days preceding this listing, Qilin claimed 122 other victims, positioning it as one of the most active ransomware operations. The group primarily targets the Business Services, Manufacturing, and Technology sectors, with a majority of victims located in the United States, France, and Germany. Excel Consultores joins a consistent stream of victims from the services sector, including Savills France, The Myers Y Cooper, Jubilee Jobs, and ABM Enviro, while also extending the group’s operational reach into Mexico.
Technical Analysis
The stealer-log data associated with excel[.]com[.]mx presents a serious concern. Eleven employee credentials were discovered on organizational systems, including Microsoft identity infrastructure, the Mexican tax authority’s SSO portal, and internal mail and communications platforms. Additionally, eight corporate credentials were found on third-party services. Several usernames from the @excel[.]com[.]mx domain were observed across different services without evidence of rotation, and the exposure period is extensive, dating from February to late July 2026. This indicates persistent, unremediated credential exposure, posing a significant risk of corporate intrusion. Infostealer-harvested credentials are a common method of initial access for operations like Qilin. Threat actors often acquire fresh logs from underground marketplaces, validate corporate credentials, and gain access to Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the presence of these logs does not directly confirm their use by Qilin for this specific incident, the observed exposure of Microsoft identity and internal mail credentials for multiple employees aligns precisely with the typical intrusion patterns leveraged by this class of threat actors. The direct exposure of Microsoft identity data and internal mail for multiple employees represents a critical risk. Organizations should consider resetting passwords for all affected accounts, revoking active sessions and tokens, and conducting a thorough forensic review of Microsoft sign-in logs and tax portal access logs to identify any unauthorized activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.