Quick Summary
AllegedExecutive Summary
Lumenis Ltd., an Israeli technology company, was listed on ShinyHunters’ extortion portal on August 2, 2026, as identified by SOCRadar’s Dark Web Monitoring service. This is an allegation on a leak site and not a confirmed breach. The listing occurs within a consistent series of claims made by the group. Lumenis Ltd.’s operations in the technology sector, particularly within Israel, may attract such activities due to the high value of intellectual property and the sophisticated nature of cyber threats targeting this industry. In the 60 days preceding this listing, ShinyHunters claimed 18 other victims, primarily in the Technology, Education, and Consumer Services sectors, with a concentration in the United States, France, and Switzerland. Notable technology-sector victims within this timeframe include RingCentral, Inc., IC Security, Nexstar, and Ernst & Young. The pattern suggests an opportunistic selection within a preferred vertical rather than a campaign specifically targeting Israel, indicating that Lumenis Ltd.’s sector alignment is the primary driver for this targeting.
Technical Analysis
SOCRadar’s stealer-log correlation revealed a significant exposure related to the lumenis[.]com domain. Specifically, nine records were identified as internal employee authentication credentials, two were linked to customers or third parties, five represented corporate accounts on external services, and seven records could not be confidently placed. The critical aspect of this exposure is its targeting of the company’s identity infrastructure, including its Active Directory Federation Services (ADFS) federation service, which appeared twice under different usernames, and a Microsoft consumer identity endpoint accessed with an @lumenis.com username. The telemetry data indicates that the most recent records date from July 14, 2026, to July 30, 2026, with the newest record predating the leak-site listing by three days. While these exposed records run parallel to the ShinyHunters listing, the telemetry data does not definitively establish a link, nor can it confirm that these credentials were used in this specific incident. ShinyHunters typically operates as a data-extortion actor, employing tactics such as social engineering, callback phishing, and credential abuse against single SaaS tenants, rather than relying on infostealer-harvested credentials for initial access in ransomware scenarios. Therefore, the conventional ransomware kill chain does not map cleanly to this actor’s known modus operandi. Regardless of the direct connection to the ShinyHunters listing, the exposed federation credentials represent an independent security finding that warrants immediate remediation. These credentials should be treated as a critical risk due to their potential to grant access to sensitive identity infrastructure and corporate applications. Organizations should consider this a significant exposure requiring proactive measures, irrespective of the final outcome or verification of the extortion group’s claim.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.