TenSparrows Data Breach

Alleged

Ransomware claim involving TenSparrows.

Published: Jul 30, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
TenSparrows
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Jul 30, 2026

Executive Summary

TenSparrows, a U.S. organization, has been listed as a victim of the Qilin ransomware group, with the listing dated July 30, 2026. SOCRadar’s initial threat intelligence analysis observed this listing, which is particularly concerning given the nature of the exposed credentials. The source data does not specify TenSparrows’ industry, but companies in sectors such as Business Services, Manufacturing, and Technology are generally attractive targets for ransomware operators due to the potential for significant impact and larger ransom payouts. The timing of the credential exposure, spanning nearly nine months without evidence of rotation, further exacerbates the risk. The Qilin ransomware operation has been highly active, claiming 122 other victims in the 60 days preceding this listing. Its recent activity shows a strong focus on Business Services, Manufacturing, and Technology sectors, primarily targeting organizations in the United States, France, and Germany. Notable recent U.S. victims include Affinity Capital, Prenisac, Byonyks, and Wilbert’s. TenSparrows aligns with Qilin’s predominant targeting of U.S. entities, although its specific sector could not be definitively matched from the available data.

Technical Analysis

The compromised credential data related to TenSparrows involves five records originating from SOCRadar’s stealer-log sample, all linked to a single corporate account with the domain @tensparrows[.]com. These records were captured over a substantial period, originating in September 2025 and extending to June 2026, indicating a persistent exposure. The affected account is associated with Microsoft Entra ID, the organization’s cloud identity system. Notably, one of the captured records documents a tenant-specific OAuth2 authorization flow, suggesting active session or token negotiation rather than simple credential reuse. The lack of any credential rotation over this nine-month window implies the account was never disabled or reset, escalating the risk to a live corporate intrusion scenario. For ransomware groups like Qilin, credentials harvested by infostealers serve as a primary vector for initial access. Threat actors, or their associated initial access brokers, frequently acquire fresh logs from underground marketplaces. They then validate these corporate credentials to gain unauthorized entry into systems such as Microsoft 365, VPNs, or remote access portals. This is often a precursor to deploying ransomware. While the presence of these exposed credentials does not definitively confirm that Qilin accessed TenSparrows’ network, a persistently exposed Entra ID identity with a captured OAuth flow represents a profile commonly exploited in such attacks. Immediate actions should include resetting the compromised password, revoking all active sessions and tokens, and thoroughly reviewing Entra ID sign-in and token-issuance logs for any suspicious activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.