InVentry Data Breach

Alleged

Ransomware claim involving InVentry

Published: Aug 19, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
InVentry
Industry
Technology
Threat Actor
Qilin
Date of Incident
Aug 19, 2026

Executive Summary

Qilin ransomware added InVentry, a UK-based visitor management and safeguarding firm, to its dark web leak site on August 19, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring service. Notably, a stealer-log record related to InVentry preceded the leak-site post by 48 hours, indicating a potential pre-attack reconnaissance phase. The nature of InVentry’s business, which involves managing visitor access and safeguarding information, could make it an attractive target for threat actors seeking sensitive data or operational disruption. In the 60 days prior to this listing, Qilin claimed approximately 196 victims, with a strong focus on the Manufacturing, Professional Services, and Technology sectors. The ransomware group predominantly targets victims in the United States, Germany, and France. Recent activity shows overlaps with the UK and technology sectors, including previous claims against INVENSITY (Germany, technology), MOSAID Technologies (Canada, technology), ASCII Group (Japan, technology), and Botek (Germany, manufacturing). InVentry’s listing aligns with Qilin’s pattern of targeting technology-adjacent companies.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for the domain inventry[.]co.uk revealed 25 records, with 23 of them containing employee credentials that appeared to be exposed against organizational systems. The primary focus of this exposure was on Microsoft 365 identity infrastructure (login.microsoftonline[.]com), InVentry’s Zendesk support platform (inventry.zendesk[.]com), and a field-operations SaaS tool (manage.fastfieldforms[.]com). An additional record indicated the same corporate email was present on a third-party service. These records spanned from February to August 2026, with the most recent dated August 17, just two days before Qilin’s public listing of InVentry. This pattern of corporate identity access surfacing in stealer logs shortly before a ransomware group posts a victim aligns with the pre-staging tactics observed in previous Qilin incidents. While these stealer-log findings do not definitively confirm that these specific credentials were exfiltrated by or used by Qilin’s operators for a ransomware attack, the timing and the nature of the access are consistent with how such incidents typically unfold. The presence of credentials for critical systems like Microsoft 365 and Zendesk indicates a potential pathway for unauthorized access or data compromise. One identified record referenced inventryuk[.]thesentinel[.]io, a subdomain that is not clearly associated with InVentry’s known infrastructure. This anomaly warrants internal investigation to determine if it represents a legitimate internal asset or potentially attacker-controlled infrastructure. The analysis of the stealer logs also identified a non-standard subdomain that requires further scrutiny to ascertain its legitimacy and association with InVentry’s operations.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.