Regency Centers Data Breach

Alleged

Ransomware claim involving Regency Centers

Published: Aug 20, 2026 IAH6477
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Regency Centers
Industry
Finance
Threat Actor
IAH6477
Date of Incident
Aug 20, 2026

Executive Summary

Regency Centers, a United States-based retail and real estate company, has been identified as a victim of the IAH6477 ransomware group. The group listed Regency Centers on its dark web portal on August 20, 2026, a discovery made through SOCRadar’s Dark Web Monitoring service. As a publicly traded Real Estate Investment Trust (REIT), Regency Centers focuses on owning and operating grocery-anchored shopping centers across the U.S., making it a significant target within the commercial real estate sector. In the 60 days preceding this listing, IAH6477 claimed three other victims, all located in the United States. This relatively small number suggests the group may be either new or highly selective in its targeting. IAH6477 has shown a propensity for attacking the Technology, Financial Services, and Retail & E-Commerce sectors. Past victims attributed to IAH6477 include Acima and other U.S. commercial organizations. Regency Centers, with its substantial employee base and extensive property portfolio, represents a high-value target for cybercriminals.

Technical Analysis

SOCRadar’s analysis of the regencycenters.com domain within stealer-log telemetry revealed a significant exposure. A query covering June through August 2026 yielded 25 records, with 23 of these identified as INTERNAL_AUTH_EMPLOYEE credentials. These compromised credentials provided access to Regency Centers’ Okta Single Sign-On (SSO) infrastructure, the applications portal (appsportal.regencycenters.com), and other enterprise platforms. This represents a high-confidence risk profile for corporate intrusion, given the repeated exposure of SSO credentials over a two-month period, which serves as a strong pre-breach indicator. The observed persistence and targeting of Okta are consistent with the operational patterns of ransomware groups aiming to establish and maintain access before executing encryption. For ransomware operations, particularly those involving groups like IAH6477, credentials harvested by infostealers are a primary method of initial access. Threat actors or initial access brokers often acquire fresh credential logs from underground markets, validate them, and then use them to gain access to platforms such as Microsoft 365, VPNs, or SSO solutions before deploying ransomware. While the stealer-log data does not definitively confirm that IAH6477 specifically utilized these compromised credentials, the exposure of 23 corporate SSO credentials, including Okta, over two months constitutes one of the most robust pre-breach indicators observable through this type of telemetry. Immediate actions for CTI teams should include rotating Okta credentials, revoking active sessions, and thoroughly reviewing access logs.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.