Quick Summary
AllegedExecutive Summary
THL, an organization based in Finland, has been listed as a victim by the Qilin ransomware group. The claim was published on July 14, 2026, and was flagged by SOCRadar’s Dark Web Monitoring service. While THL’s specific sector was not identified in the source data, the geographical focus of Qilin’s victims predominantly lies in the United States, making THL’s listing notable as a Nordic target outside their usual pattern. The Qilin ransomware group has been highly active in the 60 days preceding this listing, claiming numerous victims across business services, manufacturing, and consumer services. Their victim base is heavily skewed towards the United States, followed by Australia and the United Kingdom.
Technical Analysis
Initial access for ransomware attacks often involves credentials harvested by infostealers. SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the thl[.]com domain. The compromised data included corporate credentials for internal systems (192.168.1.1 and n[.]thl[.]com) and external platforms (thl[.]sokrio[.]com). The recurring usernames across these services suggest credential reuse, a common precursor to workstation compromise. The exposed credentials remained unrotated for nearly a year, from August 2025 to July 2026. These exposed credentials, while not definitively linked to Qilin’s direct use, align with the typical initial access kill chain observed for such ransomware incidents. Organizations are advised to rotate all exposed credentials and conduct endpoint investigations on affected users.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.