Keystone Homes Data Breach

Alleged

Ransomware claim involving Keystone Homes.

Published: Jul 6, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Keystone Homes
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Jul 6, 2026

Executive Summary

Keystone Homes, a construction company based in the United States, was listed as a victim by the Qilin ransomware group on their dark web portal on July 6, 2026. This incident was identified by SOCRadar’s Dark Web Monitoring service. Qilin has been highly active recently, with a significant number of victims listed in the 60 days prior to this event. The group primarily targets organizations in the business services, manufacturing, and consumer services sectors, with a geographical focus on the United States, Australia, and the United Kingdom. Keystone Homes aligns with Qilin’s strong presence in the United States, although the construction industry is slightly outside the group’s top three targeted sectors.

Technical Analysis

SOCRadar’s analysis found no direct correlation for gokeystone.com in their stealer-log telemetry for the 60 days preceding the listing. However, this absence does not rule out the possibility of compromise, as credentials may have been exposed through alternate domains, personal email aliases, or in data feeds not covered by the query. The technical analysis highlights that initial access for groups like Qilin often involves the use of credentials harvested from stealer logs, which are then used to gain access to corporate systems via platforms like Microsoft 365 or VPNs. CTI teams are advised to continue monitoring and implement proactive credential hygiene measures, as a null query result should not be interpreted as a sign of exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.