Quick Summary
AllegedExecutive Summary
Touring Club Suisse, Switzerland’s largest mobility club, was identified as a victim of the qilin ransomware group on September 20, 2026. The organization, which operates the website tcs[.]ch, is a significant entity within Switzerland’s service sector. The claim is distinguished by accompanying stealer-log data, indicating a potential compromise beyond a simple leak-site listing. Given its role in managing mobility and travel information, TCS could be an attractive target for threat actors seeking sensitive personal and customer data. The qilin ransomware group has been highly active recently, claiming 243 victims in the past 60 days. Their primary targets include organizations in the Manufacturing, Professional Services, and ‘Other’ sectors. While Switzerland is not qilin’s most frequently targeted country, the group does operate within its scope. Touring Club Suisse falls into the ‘Other’ category, aligning with qilin’s typical targeting profile.
Technical Analysis
Analysis of the domain tcs[.]ch revealed 20 user records within TCS-owned infrastructure. The exposed endpoints were identified as webmail.tcs[.]ch and ereport.tcs[.]ch. Notably, the compromised access profile appears to be “Customer ATO” (Account Takeover), suggesting that the credentials exposed were those of customers rather than internal staff. All identified activity is dated within September 2026, which closely correlates with the date qilin listed the organization on its dark web portal. The exposure of customer accounts on these webmail and reporting portals presents a significant risk, as these accounts likely contain personal member data. For an organization like Touring Club Suisse, which handles mobility and travel information for a broad customer base across Switzerland and Europe, this data exposure could have severe implications, especially if portal access is not adequately segregated from backend member databases. Immediate recommended actions include enforcing Multi-Factor Authentication (MFA) for all accounts and implementing a customer password-reset notification system. Continued monitoring of dark web sources and stealer-log feeds for any further activity related to Touring Club Suisse is also advised, alongside proactive credential hygiene checks for customer-facing portals.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.