Quick Summary
AllegedExecutive Summary
Gellibrand Support Services has been listed as a victim of the Anubis ransomware group on September 9, 2026. This listing was observed via SOCRadar’s Dark Web Monitoring service. As an organization operating in the professional services sector, Gellibrand provides specialized support and advisory functions. While the specific country of operation was not detailed in the listing, Anubis has recently targeted organizations across various sectors, including Healthcare, Financial Services, and Manufacturing, and has also included professional services firms in its victimology. Anubis has been active, claiming nine other victims within the preceding 60 days. The group’s targeting appears to span multiple industries, with a notable concentration in Healthcare, Financial Services, and Manufacturing, but also extending to professional services. Their victim base is primarily located in the United States, United Kingdom, and Germany. Gellibrand’s profile aligns with other recently listed victims such as Marlborough Partners, Caduceus Medical Group, Interim HealthCare (Head office), and Scholle IPN / SIG, all of which are also in the professional services or consultancy space.
Technical Analysis
The source listing for Gellibrand Support Services did not provide an organizational domain. Consequently, a direct query for stealer-log data associated with Gellibrand’s specific namespace could not be performed. Therefore, any analysis of potential credential exposure relies solely on the information presented in the threat actor’s listing. The absence of a domain for querying infostealer databases means that no direct correlation regarding pre-intrusion credential compromise could be established through this method. It is crucial to understand that the lack of query results does not confirm that Gellibrand Support Services was unaffected by credential theft; rather, it indicates a limitation in the available data for analysis. Assessment: Without a specific organizational domain, the ability to correlate potential pre-intrusion activity through infostealer logs is unavailable. This represents a gap in the data, not a definitive finding that no compromise occurred. The absence of a query result does not preclude the possibility that credentials were compromised. Next Steps: Monitor subsequent Anubis releases for any new claims or details pertaining to Gellibrand Support Services. If Gellibrand’s organizational domain becomes known, a stealer-log query should be initiated. Regardless of domain visibility, proactive credential hygiene measures and thorough review of access logs are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.