Quick Summary
AllegedExecutive Summary
Keysight, a technology company based in the United States, has been identified as a victim on the Everest ransomware group’s dark web portal, with the listing published on August 5, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. Operating within the technology sector, Keysight falls into the group’s most frequently targeted industry. This incident aligns with Everest’s recent operational pattern, which has heavily focused on technology vendors over the past two months. In the 60 days leading up to this listing, Everest claimed 18 other victims. The group consistently targets organizations in the technology, professional services, and energy and utilities sectors. Geographically, its primary victim base is located in the United States, India, and the United Arab Emirates. Notable previous victims with similar profiles to Keysight, such as US-based technology companies, include Conway Analytics, Formulatrix, Alzone Software, and Allied Telesis. While Keysight is a significantly larger and more established entity than many of these previous targets, it matches the group’s sector focus precisely.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry related to initial access vectors revealed a significant credential exposure for the keysight.com domain. Within a sample of 25 records, two credentials were identified as belonging to employees using organization-owned systems, including single sign-on endpoints. An additional record indicated a corporate user authenticating to a third-party SaaS platform. The remaining records in the analyzed slice comprised consumer or generic accounts interacting with public-facing login portals, which diminishes the clarity of corporate compromise indicators. This suggests a scenario with limited but confirmed employee-level credential exposure, alongside a larger volume of less relevant customer account data. For ransomware groups like Everest, credentials harvested by infostealers are a known method for initial access. Threat actors or initial access brokers often source these logs from underground marketplaces, validate corporate credentials, and use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that these specific credentials were exploited by Everest, the presence of SSO-adjacent employee credentials warrants security attention. Given this context, cybersecurity teams tracking this listing should prioritize credential rotation and session invalidation for the affected identity infrastructure. The limited nature of the identified employee credential exposure should not be interpreted as reassurance that a compromise has not occurred or cannot be exploited. Continuous dark web monitoring and proactive credential hygiene checks are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.