Quick Summary
AllegedExecutive Summary
Anubis ransomware has targeted Marlborough Partners, a UK-based financial advisory and investment firm serving corporate and institutional clients, listing them on its dark web portal on September 2, 2026. This claim was identified by SOCRadar’s Dark Web Monitoring service. While the listing is unverified, the financial services sector and its handling of sensitive client data make it an attractive target for ransomware operations. In the 60 days preceding this listing, Anubis claimed nine victims, primarily in the Healthcare and Financial Services sectors within the United States and United Kingdom. Notable recent victims include Cameron Regional Medical Center, Interim HealthCare, BLACKBURN’S, and Cleaver-Brooks. The inclusion of Marlborough Partners marks Anubis’s second claim against a financial services firm in this period and its most recent target in the United Kingdom, indicating a growing focus on this region.
Technical Analysis
SOCRadar’s investigation into the domain marlboroughpartners[.]com using its stealer-log monitoring returned no relevant records within the queried dataset. However, this absence of data does not confirm that Marlborough Partners is unaffected. Stealer-log data is often paginated and filtered, meaning credentials may exist in adjacent datasets, be associated with personal email aliases, or reside in feeds not covered by the query. For a financial services firm of Marlborough Partners’ profile, a null result from a limited query offers no definitive security assurance. The Anubis ransomware group is noted for targeting high-value sectors, including financial and healthcare organizations. The presence of Marlborough Partners on their leak site, regardless of the current stealer-log findings, necessitates a proactive security posture. Continued monitoring of dark web and stealer-log sources for any associated credentials or indicators of compromise is recommended. Organizations in similar sectors should also conduct thorough audits of external access points, such as VPNs, remote-access portals, and federated identity systems, to mitigate potential intrusion vectors.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.