ISSVC Data Breach

Alleged

Ransomware claim involving ISSVC

Published: Jul 22, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ISSVC
Industry
Technology
Threat Actor
Chaos
Date of Incident
Jul 22, 2026

Executive Summary

ISSVC, a technology company based in Singapore, has been listed as a victim on the Chaos ransomware group’s dark web portal, published on July 22, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. Operating in the technology sector, the company sits among the IT and services providers that regularly appear on extortion portals. Its listing is a comparatively rare Singapore entry within a Chaos victim population that has been dominated by US organizations. In the 60 days prior to this listing, Chaos has claimed 10 other victims across its leak portal. The group has shown a targeting pattern weighted toward technology, healthcare, and business services. Geographically, its victims are concentrated in the United States, with occasional listings in Singapore and Germany. Other recent Chaos listings that overlap with ISSVC’s profile — technology and services organizations — include Radia Inc. PS, Grand Isle Shipyard Inc., AireSpring, and Wikoff Color Corporation. ISSVC fits the group’s technology lean but diverges from its heavy US concentration as one of its few Singapore-based targets.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the issvc.com domain. The queried slice returned nine records: six showed the same corporate username authenticating to Microsoft identity endpoints, a direct employee-credential exposure on the organization’s SSO, and three showed a second corporate username on third-party consumer services, a workstation-compromise indicator. The recurrence of the same identity-provider account across multiple timestamps points to persistent access or unrotated credentials. The dominant profile is corporate intrusion risk, with a long-tailed freshness window running from March 2024 to mid-July 2026. For ransomware groups such as Chaos, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Chaos, repeated corporate logins to Microsoft identity endpoints are consistent with the kill chain typically observed for this class of incident, and it makes credential resets, MFA enforcement, and sign-in log review a priority for organizations fitting this profile.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.