Quick Summary
AllegedExecutive Summary
Barracuda ransomware has listed i2i-systems as an alleged victim on its dark web portal as of September 13, 2026. i2i-systems is a Turkey-based technology company. This listing represents an extortion claim, not a confirmed breach, as information on ransomware sites cannot always be independently verified. The threat intelligence was identified through SOCRadar’s Dark Web Monitoring service. Barracuda ransomware has claimed 9 other victims in the past 60 days, indicating a selective approach to its targeting. Its recent victims operate in the Healthcare, Manufacturing, and Technology sectors, with operations primarily located in the United States, South Korea, and Turkey. Notable past victims include Micro-Comm Inc., Clinical Associates of the Finger Lakes (CAFL), and Namyang Industrial Co., Ltd. i2i-systems’ inclusion aligns with Barracuda’s recent focus on the Technology sector in Turkey.
Technical Analysis
Ransomware operators such as Barracuda commonly gain initial access by exploiting stolen login credentials, often acquired from underground markets. This method circumvents the need to exploit software vulnerabilities, allowing them to directly access corporate VPN portals or Microsoft 365 accounts before commencing an attack. SOCRadar’s threat intelligence database was queried for matching credentials associated with i2i-systems[.]com. The query returned no matching credentials for i2i-systems[.]com within the queried dataset. However, it is important to note that this search is bounded and may not encompass all available data. Credentials could exist under alternate corporate domains, use personal email aliases, or may have been used and rotated prior to indexing in the feeds that SOCRadar monitors. Therefore, the absence of identified credentials does not definitively rule out a compromise. Given the potential for credential exposure, organizations should assume that their exposure picture may be incomplete. It is recommended that leadership prioritize a forced password reset for all internet-facing accounts and consider continuous dark web monitoring. Additionally, proactive credential hygiene checks, including reviewing multi-factor authentication configurations and monitoring remote access logs, are advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.