Quick Summary
AllegedExecutive Summary
On July 28, 2026, Deadlock ransomware listed Takis srl, an Italian healthcare company, as a victim on its dark web portal. SOCRadar’s Dark Web Monitoring service identified this listing. The associated stealer-log signal was confirmed to be real, although its scope was narrower than initially suggested. The healthcare sector is considered a recurring, though less dominant, target for Deadlock. Italy is Deadlock’s most frequently targeted country, indicating that Takis srl aligns with the group’s typical geographical focus. Over the preceding 60 days, Deadlock claimed 25 other victims. These victims were primarily in the manufacturing, general, and healthcare sectors, with operations in Italy, Spain, and Chile. This pattern highlights Deadlock’s strong focus on Italy. Recent victims listed by the group include BioResearch, Pasello, CNA, and CAD93, demonstrating a consistent targeting of similar organizations and geographies.
Technical Analysis
A stealer-log check on takisbiotech[.]com found three records. However, all these records pertained to a single consumer-email account that logged into the WordPress endpoint of the site. No corporate email addresses from @takisbiotech[.]com were found. The same login credentials were used repeatedly from March to July 2026 without any rotation. This suggests that the exposure is related to customer account takeovers or credential reuse, rather than a direct compromise of employee accounts. Infostealer logs are a common vector for initial access exploited by the Deadlock ransomware group. The presence of unrotated credentials on victim infrastructure is a known hygiene gap that facilitates their operations. However, in this instance, the exposed credentials were for a public-facing WordPress login, not a corporate identity. Therefore, this finding should be treated as a monitoring signal rather than confirmed access. As a cautionary measure, organizations should pursue credential hygiene enhancements and review their content management system (CMS) access logs. This incident underscores the importance of monitoring public-facing applications and ensuring robust credential management practices to prevent potential exploitation. Continued dark web monitoring and proactive credential hygiene checks are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.