Lantis Enterprises, Inc. Data Breach

Alleged

Ransomware claim involving Lantis Enterprises, Inc.

Published: Aug 5, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Lantis Enterprises, Inc.
Industry
Technology
Threat Actor
INC Ransom
Date of Incident
Aug 5, 2026

Executive Summary

Lantis Enterprises, Inc., a technology services company based in the United States, has been identified as a victim by the INC Ransom threat group. The listing was published on their dark web portal on August 5, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. Lantis Enterprises operates within the technology services sector and is part of a significant number of US-based victims claimed by INC Ransom, aligning with the group’s predominant targeting patterns. In the 60 days preceding this listing, INC Ransom claimed 35 other victims, indicating a high-volume operation. The group predominantly targets the business services, manufacturing, and healthcare sectors, with the United States being their primary geographic focus, followed by Mexico and Canada. Other US technology and services organizations recently claimed by INC Ransom include Quantinuum, Signazon_USA, TRULITE GLASS & ALUMINUM SOLUTIONS, and clintonhealthaccess.org. While Lantis Enterprises matches the group’s typical US victim profile, the technology sector is a secondary vertical compared to their more frequent targets.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a credential exposure related to the domain lantisnet.com. A single credential was recovered that is associated with an internal workforce management and timekeeping platform. The username was masked but shared a pattern consistent with the corporate email domain, and the URL matched a known internal subdomain. Although this single record is limited evidence and the masking prevents definitive attribution, the exposure of credentials for an internal business system, rather than a public-facing portal, is considered significant. HR and timekeeping platforms are often targeted due to their sensitive workforce data and their typical placement outside the primary identity management perimeter. For ransomware operations like INC Ransom, credentials harvested by infostealers represent a documented initial access vector. Threat actors or initial access brokers often source these credentials from underground marketplaces, validate them, and use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that these specific credentials were used by INC Ransom, a validated credential on an internal application is a type of access that access brokers commonly package for resale. Given the listing on the INC Ransom leak portal and the observed credential exposure, CTI teams tracking this incident should treat the exposed identity as a persistent risk. Prioritizing credential rotation and session invalidation is recommended over a point-in-time assessment. Continued dark web monitoring for further listings and stealer-log monitoring for additional exposures should be maintained.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.