Translarity Data Breach

Alleged

Settra ransomware claim involving Translarity

Published: Oct 3, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Translarity
Industry
IT Services
Threat Actor
Settra
Date of Incident
Oct 3, 2026

Executive Summary

Translarity, an IT services or translation technology company, was listed on Settra’s dark web leak site on October 3, 2026. This listing followed an 11-month period during which an employee’s credentials were found in stealer markets, from October 2025 through September 2026. As a company that handles confidential client projects, proprietary translation models, and sensitive personal data across various cloud platforms, Translarity’s profile makes it an attractive target for cybercriminals utilizing credential-based intrusion methods. Settra typically targets professional services and technology firms, employing a double extortion strategy. The group often leverages credentials compromised from cloud identity and collaboration platforms as their primary access vector. Over the preceding 60 days, Settra’s victimology has predominantly featured smaller and mid-sized technology organizations, which often possess valuable data but may have varying levels of cybersecurity investment.

Technical Analysis

One Translarity employee, using a partially masked email address (fra****n@translarity[.]com), was identified across 10 distinct stealer-log records spanning an 11-month timeframe. These records indicated the compromise of Microsoft IdP credentials in four instances, Box cloud storage credentials in three instances, and credentials for isaevworkshop[.]com in three instances. This persistent exposure across multiple critical platforms over nearly a year suggests a potential ongoing infostealer infection on a workstation or recurring reinfection. The combination of compromised Microsoft IdP and Box credentials is particularly concerning. Microsoft IdP access can grant broad authentication privileges within an enterprise, while Box access allows for the retrieval of stored files and shared content. Together, these credentials could provide a nearly comprehensive pathway for data exfiltration. The presence of credentials for isaevworkshop[.]com also indicates a broader potential for compromise across various online services used by the employee. Translarity should conduct endpoint forensics on the affected workstation, initiate a mandatory rotation of all Microsoft IdP and Box credentials, and thoroughly audit access logs for both platforms for the entire duration of the observed exposure (October 2025 to September 2026). Any client files accessed via Box during this period should be evaluated for unauthorized access, with affected clients notified as necessary. Implementing per-device Conditional Access policies within Microsoft Entra ID could further mitigate this specific vector going forward.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.