Pasello Data Breach

Alleged

Ransomware claim involving Pasello

Published: Jul 28, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Pasello
Industry
Technology
Date of Incident
Jul 28, 2026

Executive Summary

Pasello, an Italian technology company, was identified as a victim by the Deadlock ransomware group, which listed the organization on its leak site on July 28, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring service. Pasello’s inclusion marks the third Italian organization targeted by Deadlock in a recent surge of activity. While technology is not Deadlock’s primary focus, Italy represents the group’s most frequently targeted country, making Pasello a plausible, though not typical, target. In the 60 days preceding this incident, Deadlock claimed 25 other victims, predominantly in the manufacturing, general, and healthcare sectors. The ransomware group’s strong focus on Italy, its leading victim country, reinforces the relevance of Pasello’s location. Historically, sectors like manufacturing have seen more activity from Deadlock. Other recent victims falling within similar geographic or sectoral patterns include Hardware Asesorias Software Ltda, Takis srl, CNA, and CAD93.

Technical Analysis

SOCRadar performed a stealer-log check for the domain pasello[.]it. The query returned no direct records within the accessed dataset. It is important to note that this check utilized a paginated and partial sample of available data. This limitation means that credentials could potentially exist under a sibling domain or be associated with staff personal email aliases that were not included in the query. Therefore, the absence of observed records does not confirm that the organization is unaffected by credential compromise. The method of collecting stealer logs is a common initial access vector for ransomware operations. Threat actors or initial access brokers often purchase these logs from underground marketplaces. These compromised credentials are then validated and used to gain access to corporate accounts, potentially compromising systems through platforms like Microsoft 365, VPNs, or other remote-access portals, before the deployment of ransomware. The lack of observed exposure for Pasello does not preclude this possibility. Consequently, continued monitoring of dark web and stealer-log feeds remains a recommended security measure, alongside proactive credential hygiene checks. This includes regular password rotation, thorough review of multi-factor authentication configurations, and vigilant monitoring of activity across Microsoft 365, VPNs, and other remote-access infrastructure.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.