Quick Summary
AllegedExecutive Summary
INC Ransom has listed pushidrosal.id on its leak portal on August 4, 2026, marking it as the only Indonesian entity in the reported batch. This claim was identified by SOCRadar’s Dark Web Monitoring service. The listing uses a domain identifier, pushidrosal[.]id, which is a common practice when threat actors post infrastructure information rather than a formal company name. At present, SOCRadar’s dataset does not confirm a specific industry for the targeted organization. In the 60 days preceding this listing, INC Ransom claimed 32 other victims, maintaining a consistent mid-volume attack cadence. The group’s targets predominantly fall within the business services, healthcare, and manufacturing sectors, although a significant portion of their claimed victims have no confirmed sector. Historically, the United States has been the most frequently targeted country, with Mexico and Argentina following. This recent batch deviates from that pattern, as three out of the four listed victims are located outside the US, indicating a broader geographic scope than typically observed in the past two months. Notable similar victims with unconfirmed sectors include Oleoductos del Valle, clintonhealthaccess[.]org, Liberty Commercial Center, Inc, and Evangelical Council for Financial Accountability.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for pushidrosal[.]id, with 26 records identified. These records include 6 employee credentials on organization systems, 10 external or third-party accounts on organization systems, 1 corporate account on an external service, and 1 unclear entry. The critical endpoints identified span organizational subdomains related to identity and single sign-on services, an administrative back-office application, mail infrastructure, and an internal cloud data service. This indicates potential compromise across authentication, administration, email, and data storage functions. One corporate identity was also found on a network-vendor support portal, suggesting a possible infected endpoint. The data freshness spans from July 6 to August 4, 2026, with the latest capture coinciding with the publication date, suggesting active harvesting of credentials. The observed stealer-log exposure aligns with common initial access vectors employed by ransomware groups like INC Ransom. Operators or initial access brokers frequently source fresh credential logs from underground marketplaces, validate them, and then use them to access systems via platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this telemetry does not definitively confirm that INC Ransom utilized these specific credentials, the close proximity of the credential capture to the leak-site listing, combined with the broad range of internal systems affected, points to a substantial intrusion risk. The continuous harvesting activity suggests that any existing access may not have been remediated, indicating a potential ongoing incident that requires an immediate response.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.