Verve Portraits Pty Ltd Data Breach

Alleged

Ransomware claim involving Verve Portraits Pty Ltd

Published: Sep 3, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Verve Portraits Pty Ltd
Industry
Retail
Threat Actor
Settra
Date of Incident
Sep 3, 2026

Executive Summary

Verve Portraits Pty Ltd, an Australian retail and e-commerce company operating via verveportraits[.]com[.]au, has been listed as a victim on the settra ransomware group’s dark web portal as of September 3, 2026. SOCRadar’s Dark Web Monitoring service identified the listing. The inclusion of an Asia-Pacific retail firm extends settra’s known geographic reach well beyond its core European and North American victim base. settra claimed 32 other victims in the 60 days prior to this listing. The group concentrates most heavily in the United States, Germany, and the United Kingdom, targeting technology, professional services, and manufacturing organizations, with retail appearing alongside them in the victim pool. Recent victims with comparable small-to-mid-market profiles include Manhattan Loft Corporation Limited (United Kingdom, hospitality), Hatch Communications (United Kingdom, professional services), Zonar Systems (United States, transportation), and Zayo Group (United States, technology).

Technical Analysis

SOCRadar’s stealer-log telemetry returned no records for verveportraits[.]com[.]au in the queried slice. A null result is not the same as a clean bill of health: the query covers a paginated sample of available logs, and credentials may have surfaced under alternate domains, personal email aliases, or in feeds outside this dataset. The absence of records in this specific query does not rule out the possibility of a compromise. Infostealer-harvested credentials could potentially be used by threat actors for initial access into corporate networks, facilitating ransomware deployment or other malicious activities. It is crucial for organizations to maintain robust security practices and continuous monitoring. Monitoring of dark web portals and stealer-log feeds should be maintained to detect any further claims or related activity. Proactive credential hygiene, including regular password rotation and multifactor authentication review, is essential. Organizations should also monitor alternate corporate domains and review access logs for Microsoft 365, VPNs, and remote-access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.