Interconnect Computer Cabling Services, Inc. Data Breach

Alleged

Ransomware claim involving Interconnect Computer Cabling Services, Inc.

Published: Sep 29, 2026 m3rx
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Interconnect Computer Cabling Services, Inc.
Industry
Business Services
Threat Actor
m3rx
Date of Incident
Sep 29, 2026

Executive Summary

m3rx ransomware has listed Interconnect Computer Cabling Services, Inc. (ICCSI) on its dark web portal, with the claim dated September 29, 2026. ICCSI is a provider of computer cabling and infrastructure services catering to commercial and institutional clients throughout the United States. This listing was detected by SOCRadar’s Dark Web Monitoring service. The incident is part of a pattern of recent claims made by m3rx, targeting professional services firms across various locations concurrently. In the preceding 60 days, m3rx has claimed responsibility for seven other victims. These organizations operate within the Professional Services, Technology, and Retail & E-Commerce sectors, primarily located in the US, Brazil, and Canada. Notable recent victims with similar profiles include Otero Geeza Law P.A., CPACB, Soma Soluções em T.I., and Cipher Systems. The targeting of ICCSI aligns with m3rx’s established pattern of focusing on these industries and geographical regions.

Technical Analysis

SOCRadar’s stealer-log telemetry revealed a significant credential exposure for iccsi[.]com, involving 25 records across two corporate email addresses. These records span from February to September 2026, indicating an eight-month window of compromised credentials. The exposed credentials include access to Microsoft identity infrastructure, such as login.live.com and OAuth endpoints, as well as multiple sessions within the Procore construction project management platform from February to June 2026. Additionally, Google account authentication details were also compromised. The exposure consists of two records classified as category A (employee credentials on organization-controlled systems) and 23 records involving corporate users on third-party platforms. The prevalence of compromised third-party platform credentials suggests a widespread issue affecting user accounts across various services. The dominant pattern observed is persistent workstation compromise, which may have facilitated the continuous harvesting of these credentials over an extended period. The eight-month credential exposure, particularly involving Microsoft identity and a major project management platform like Procore, is consistent with sustained access to user workstations, potentially granting access to internal infrastructure. The multiple Procore sessions across four months suggest a workstation or account that remained compromised throughout the spring of 2026. The working hypothesis is that m3rx utilized stealer-sourced credentials as an initial access vector, a scenario supported by the observed timeline. Prioritization for immediate action should include reviewing Microsoft identity credentials, auditing Procore accounts, and conducting endpoint forensics on the two machines associated with the compromised credentials.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.