Quick Summary
AllegedExecutive Summary
Termite listed theLender on its dark web portal on September 22, 2026. theLender is a US mortgage and wholesale lending company operating in the financial services sector. The listing was identified through SOCRadar’s Dark Web Monitoring service. Termite claimed 6 other victims in the prior 60 days, concentrated in the United States and China across Manufacturing, Financial Services, and Healthcare. Recent US listings include TruAmerica Multifamily, Sealcon, Everglades Boats, and Affinia Healthcare. theLender’s US financial services profile fits Termite’s demonstrated targeting pattern directly.
Technical Analysis
SOCRadar’s stealer-log telemetry surfaced a severe exposure for thelender[.]com: 21 records spanning May 2025 through September 18, 2026 — more than 16 months of persistent, unrotated credential exposure. The breakdown: 11 employee credentials against organizational systems, 2 customer or third-party records on org infrastructure, and 3 corporate users on third-party SaaS platforms. Dominant profile: Mixed. High-value endpoints in the sample include the WordPress admin console (thelender[.]com/wp-login.php), the wholesale portal admin interface (wholesale.thelender[.]com/wp-login.php), and pro.realquest[.]com, a real-estate SaaS platform accessed by multiple corporate users. At least three distinct employee accounts appear across the 16-month window with no evidence of credential rotation. Sixteen months of exposure across a WordPress admin console, an internal wholesale portal, and a third-party lending platform is a textbook pre-intrusion foothold — the credential profile initial access brokers sell and ransomware operators buy. The stealer-log evidence doesn’t confirm Termite used these specific credentials; the breadth and persistence of the exposure make the point regardless.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.