PCA Group Sdn. Bhd. Data Breach

Alleged

Ransomware claim involving PCA Group Sdn. Bhd.

Published: Aug 25, 2026 majinahanashi
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
PCA Group Sdn. Bhd.
Industry
Business Services
Threat Actor
majinahanashi
Date of Incident
Aug 25, 2026

Executive Summary

Majinahanashi ransomware group listed PCA Group Sdn. Bhd. on its dark web portal on August 25, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring capabilities. PCA Group, operating in Malaysia, is part of the business services sector. The targeting of another Malaysian commercial entity aligns with the group’s established patterns. In the 60-day period preceding this listing, Majinahanashi claimed 19 prior victims. Their targeting has spanned sectors including hospitality and commercial, with victims identified in Malaysia, Colombia, and the United States. Notable previous victims include BONJOUR GROUP, CARIBE / SUBRA, and Grand Ion Delemen Hotel. The current victim’s profile aligns with the ransomware group’s consistent focus on Malaysian commercial and hospitality businesses, indicating a direct adherence to their typical targeting logic.

Technical Analysis

A query was performed on the domain pcagroup[.]com[.]my for stealer-log records. The query returned no records. It is important to note that the dataset queried is paginated and sampled, meaning that credentials may have surfaced in feeds that were not covered or may exist under employee personal email aliases. The absence of positive signals in this specific query does not equate to exoneration. Infostealer logs are a common source for initial access by ransomware operators. Threat actors often harvest and validate corporate credentials from these logs, subsequently using them against platforms such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. Therefore, credential hygiene checks and active domain monitoring remain crucial defensive measures.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.