Quick Summary
AllegedExecutive Summary
Park de Rochie, a business services company based in the Netherlands, was listed on the dark web portal of the Chaos ransomware group on August 25, 2026. SOCRadar’s Dark Web Monitoring service identified this listing. The Netherlands is a geographic outlier for Chaos, whose recent victims have predominantly been located in the United States, United Kingdom, and East Asia, suggesting the group may be expanding its targeting beyond its typical geographic focus. In the preceding 60 days, Chaos claimed 15 other victims, primarily in the Healthcare, Technology, and Professional Services sectors. Notable recent victims include Central Ohio Primary Care, MS Walker, Tomorrow’s Office, and Healthcare Highways. Park de Rochie’s listing suggests that Chaos is either broadening its European targeting or is less constrained by geographic patterns than previously observed. The extended eight-month window of exposed credentials associated with Park de Rochie indicates a potential long-standing access point exploited by the threat actor.
Technical Analysis
A query for parkderochie[.]com by SOCRadar returned nine records. Of these, four were employee credentials found within the organization’s own infrastructure. Notably, credentials for Exchange/OWA webmail were identified, representing a direct access point to internal communications and a potential vector for lateral movement within the network. Additionally, credentials for an internal learning management system were also part of the compromised data set. The remaining records linked a corporate user with the email domain @parkderochie[.]com to a third-party contractor management platform. These records appeared across an eight-month period, from December 2025 to August 2026. This persistent exposure suggests either a continually compromised workstation or unrotated credentials present in underground markets for an extended duration, neither of which is indicative of robust security practices. The overall profile of the exposed credentials is mixed, with a freshness window spanning from December 5, 2025, to August 3, 2026. The presence of infostealer-harvested credentials strongly suggests Chaos’s likely initial access method, as threat actors commonly validate such logs from underground markets to authenticate against webmail, VPN, or remote-access portals. The identified OWA credentials, with an eight-month exposure window, align with the access-maintenance phase often observed before ransomware deployment. It is recommended that all identified corporate account passwords be reset immediately. Additionally, Exchange audit logs should be pulled, and endpoint forensics should be performed on any device associated with the persistent contractor-platform credential.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.