Mighty Kingdom Data Breach

Alleged

Ransomware claim involving Mighty Kingdom

Published: Aug 17, 2026 Direwolf
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Mighty Kingdom
Industry
Technology
Threat Actor
Direwolf
Date of Incident
Aug 17, 2026

Executive Summary

Direwolf listed mightykingdom[.]com on its dark web portal on August 17, 2026, an event identified by SOCRadar’s Dark Web Monitoring service. Mighty Kingdom, headquartered in Adelaide, Australia, is a game developer engaged in projects for mobile, console, and interactive media, with established partnerships with major platform holders. The company’s operations and data may attract ransomware or extortion activity due to its position within the technology sector and its handling of proprietary development information. In the 60 days preceding this listing, Direwolf claimed 20 other victims. The ransomware group predominantly targets the Technology, Healthcare, and Professional Services sectors, with a geographical focus on the United States, United Kingdom, and Brazil. Notable previous victims within the technology sector and in Australia include Eva AI Limited, Wishfully Studios, DXS International, and TOTVS. Mighty Kingdom’s inclusion aligns with Direwolf’s established targeting patterns.

Technical Analysis

SOCRadar’s query for stealer-log records associated with mightykingdom[.]com yielded five entries. These records, dated between December 2025 and June 2026, exclusively used the corporate email domain @mightykingdom[.]com across various third-party services. The compromised services included Google Workspace IdP session endpoints (accounts.google[.]com/addsession), Apple TestFlight team management, and Pivotal Tracker, the latter linked via a Google account. Two masked corporate usernames, “phi****p” and “dan****n,” were observed across multiple services and timestamps, suggesting continuous workstation compromise or a prolonged period of credential reuse without rotation, spanning at least six months. The presence of credentials linked to Google Workspace IdP is particularly significant. If Mighty Kingdom utilizes Google Workspace for its operations, this type of credential could grant access to organizational email, Google Drive, and potentially other connected Software-as-a-Service (SaaS) applications managed through the identity provider. The observed data spans from December 2025 to June 2026, indicating a potential early access point around December 2025. The pattern of compromised corporate credentials appearing on third-party services, coupled with the extended timeframe of six months, strongly suggests a workstation compromise or a similar persistent access vector. This scenario aligns with the preparatory stages of a ransomware attack, where threat actors gather credentials to facilitate further lateral movement and data exfiltration. The timeframe of the logs, particularly the December 2025 entry, indicates a crucial window for forensic investigation to determine the scope and initial access method. Next Steps: – Rotate Google Workspace credentials for phi****p and dan****n immediately. – Audit Google Workspace session logs from December 2025 onward. – Review Apple TestFlight and Pivotal Tracker access during the same window. – Assess scope of any source code or project data that may have been staged for exfiltration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.