Quick Summary
AllegedExecutive Summary
Nolan Consulting Group, a professional services firm based in the United States, was listed on September 5, 2026, as a victim of the qilin ransomware group. This listing was identified through SOCRadar’s Dark Web Monitoring service, indicating a continuation of qilin’s campaign targeting professional services firms. Consulting companies are often targeted due to their access to sensitive data and privileged information across multiple client environments, making them attractive targets for ransomware operators seeking leverage beyond a single organization. Over the past 60 days, qilin has claimed 242 other victims, with Manufacturing and Professional Services being its most frequently targeted industries. The United States, Germany, and Italy are identified as the primary geographic locations of its victims. Recent US-based professional services firms that have been listed by qilin include Bauman Law Group, LAPoco Architects, Integrex RCM, and Clear Align. This consistent targeting of specific sectors and geographies suggests a deliberate and focused strategy by the qilin ransomware group, rather than simply opportunistic attacks.
Technical Analysis
SOCRadar’s query of stealer-log data for the domain “nolancg[.]com” returned no records within the sampled dataset. It is important to note that this null result does not confirm that the organization is unaffected by a compromise. Consulting firms often handle credentials related to their clients and may utilize personal email aliases for internal communications, which could lead to credentials existing within feeds not directly associated with the primary corporate domain. The absence of records for nolancg[.]com in the sampled stealer-log data does not rule out the possibility of credential-based access. Threat actors often exploit compromised credentials obtained through various means, including infostealer malware, to gain initial access to target networks. Therefore, continued monitoring of the corporate domain for suspicious activity remains crucial. The current findings underscore the importance of comprehensive dark web monitoring and proactive security measures. Given the nature of the professional services industry and the known tactics of ransomware groups like qilin, organizations should consider implementing continuous dark web monitoring, conducting regular credential hygiene checks, rotating passwords, and reviewing multi-factor authentication configurations for all sensitive accounts and remote access points.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.